Stored cross site scripting in Craft CMS
Moderate severity
GitHub Reviewed
Published
May 26, 2023
to the GitHub Advisory Database
•
Updated Nov 12, 2023
Description
Published by the National Vulnerability Database
May 26, 2023
Published to the GitHub Advisory Database
May 26, 2023
Reviewed
May 26, 2023
Last updated
Nov 12, 2023
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. This issue was patched in version 4.4.12.
References