Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcrj-6ffc-v7hq

Опубликовано: 03 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Craft CMS Stored Cross-site Scripting Injection Vulnerability

Summary

When you insert a payload inside a label name or instruction of an entry type, an XSS happens in the quick post widget on the admin dashboard.

PoC

Complete instructions, including specific configuration details, to reproduce the vulnerability.

Impact

Tested with the free version of Craft CMS 4.3.6.1

Пакеты

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 4.0.0-RC1, < 4.3.7

4.3.7

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 3.7.24, < 3.7.64

3.7.64

EPSS

Процентиль: 93%
0.0955
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7.

EPSS

Процентиль: 93%
0.0955
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79