Описание
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.
Уязвимые конфигурации
Конфигурация 1Версия до 4.4.11 (включая)
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00159
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
EPSS
Процентиль: 37%
0.00159
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79