Логотип exploitDog
bind:CVE-2023-33194
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-33194

Количество 2

Количество 2

nvd логотип

CVE-2023-33194

больше 2 лет назад

Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3wxg-w96j-8hq9

больше 2 лет назад

CraftCMS stored XSS in Quick Post widget error message

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-33194

Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wxg-w96j-8hq9

CraftCMS stored XSS in Quick Post widget error message

CVSS3: 3.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу