CVE-2023-33194

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in packagist/craftcms/cms

Identifiers

CVE-2023-33194, GHSA-3wxg-w96j-8hq9

Package Slug

packagist/craftcms/cms

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

Craft is a CMS for creating custom digital experiences on the web. The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.

Affected Versions

All versions starting from 3.0.0 before 3.8.6, all versions starting from 4.0.1 before 4.4.6

Solution

Upgrade to versions 3.8.6, 4.4.6 or above.

Last Modified

2023-05-29

source