PT-2023-24211 · Craft · Craft
Whitebearvn
·
Published
2023-05-26
·
Updated
2023-06-02
·
CVE-2023-33194
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Craft versions prior to 4.4.6
Description
The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. An older issue fixed the XSS in label HTML but did not address it when clicking save.
Recommendations
For versions prior to 4.4.6, update to version 4.4.6 to resolve the issue. As a temporary workaround, consider avoiding the use of the Quick Post feature until the update is applied. Restrict access to the admin dashboard and limit the ability to create or edit sections and entries to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Craft