Описание
craftcms/cms vulnerable to cross site scripting in RSS feed widget
A malformed title in the feed widget of craftcms/cms can deliver an XSS payload. This has been resolved in this commit.
Пакеты
Наименование
craftcms/cms
composer
Затронутые версииВерсия исправления
>= 3.0.0, <= 3.8.3
3.8.4
Наименование
craftcms/cms
composer
Затронутые версииВерсия исправления
>= 4.0.0, <= 4.4.3
4.4.4
Связанные уязвимости
CVSS3: 6.1
nvd
больше 2 лет назад
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.