Логотип exploitDog
bind:CVE-2023-2817
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-2817

Количество 2

Количество 2

nvd логотип

CVE-2023-2817

больше 2 лет назад

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7x94-jx75-3gh6

больше 2 лет назад

Stored cross site scripting in Craft CMS

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-2817

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7x94-jx75-3gh6

Stored cross site scripting in Craft CMS

CVSS3: 5.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу