Описание
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
Ссылки
- Patch
- Release Notes
- ExploitPatchVendor Advisory
- Patch
- Release Notes
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.4.6 (исключая)
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00298
Низкий
5.5 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-80
CWE-79
Связанные уязвимости
EPSS
Процентиль: 53%
0.00298
Низкий
5.5 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-80
CWE-79