CVE-2023-33197

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in packagist/craftcms/cms

Identifiers

CVE-2023-33197, GHSA-6qjx-787v-6pxr

Package Slug

packagist/craftcms/cms

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.

Affected Versions

All versions before 4.4.6

Solution

Upgrade to version 4.4.6 or above.

Last Modified

2023-05-29

source