PT-2023-24211 · Craft · Craft
Whitebearvn
·
Publicado
2023-05-26
·
Atualizado
2023-06-02
·
CVE-2023-33194
CVSS v3.1
3.7
Baixa
| Vetor | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Craft versions prior to 4.4.6
Description
The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. An older issue fixed the XSS in label HTML but did not address it when clicking save.
Recommendations
For versions prior to 4.4.6, update to version 4.4.6 to resolve the issue. As a temporary workaround, consider avoiding the use of the Quick Post feature until the update is applied. Restrict access to the admin dashboard and limit the ability to create or edit sections and entries to minimize the risk of exploitation.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Craft