Stored Cross-Site Scripting Vulnerability in Craft CMS by Pixel & Tonic
CVE-2023-2817
What is CVE-2023-2817?
A post-authentication stored cross-site scripting vulnerability has been identified in Craft CMS versions up to 4.4.11. This vulnerability allows an attacker to inject HTML, including script tags, into field names. When these fields are incorporated into categories or sections, the malicious scripts are executed when users access the Categories or Entries pages. This flaw poses a significant risk as it can lead to unauthorized access to sensitive information and compromise the integrity of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Craft CMS versions prior or equal to version 4.4.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
