Server side cross-site scripting In craftcms/cms
Description
Craft CMS Stored Cross-site Scripting Injection Vulnerability
Summary
When you insert a payload inside a label name or instruction of an entry type, an XSS happens in the quick post widget on the admin dashboard.
PoC
Complete instructions, including specific configuration details, to reproduce the vulnerability.
Impact
Tested with the free version of Craft CMS 4.3.6.1
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.3.7, 3.7.64 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.