PT-2024-12554 · Feed Me+1 · Feed Me+1

Angrybrad

·

Published

2024-01-30

·

Updated

2024-08-02

·

CVE-2023-36260

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Feed Me plugin version 4.6.1 Craft CMS version 4.6.1 Craft CMS version 4.6.1.1
Description An issue was discovered that allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected.
Recommendations For Feed Me plugin version 4.6.1, update to a version that fixes the issue. For Craft CMS version 4.6.1, update to a version that fixes the issue. For Craft CMS version 4.6.1.1, update to a version that fixes the issue. As a temporary workaround, consider restricting access to the Feed-Me Name and Feed-Me URL fields until a patch is available.

Fix

DoS

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2023-36260
GHSA-6P78-F7H9-6838

Affected Products

Craft Cms
Feed Me