logo

Database

Server side cross-site scripting In craftcms/cms

Description

Craft CMS Stored Cross-site Scripting Injection Vulnerability

Summary

When you insert a payload inside a label name or instruction of an entry type, an XSS happens in the quick post widget on the admin dashboard.

PoC

Complete instructions, including specific configuration details, to reproduce the vulnerability.

Impact

Tested with the free version of Craft CMS 4.3.6.1

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions