Craft CMS stored XSS in indexedVolumes
Description
Published to the GitHub Advisory Database
May 26, 2023
Reviewed
May 26, 2023
Published by the National Vulnerability Database
May 26, 2023
Last updated
Nov 8, 2023
Summary
XSS can be triggered via the Update Asset Index utility
PoC
XSS will be triggered
Json response volumes name makes triggers the payload
It’s run on every POST request in the utility.
Resolved in craftcms/cms@8c2ad0b
References