Stored Cross-Site Scripting Vulnerability in Craft CMS by Pixel & Tonic
CVE-2023-2817
5.4MEDIUM
What is CVE-2023-2817?
A post-authentication stored cross-site scripting vulnerability has been identified in Craft CMS versions up to 4.4.11. This vulnerability allows an attacker to inject HTML, including script tags, into field names. When these fields are incorporated into categories or sections, the malicious scripts are executed when users access the Categories or Entries pages. This flaw poses a significant risk as it can lead to unauthorized access to sensitive information and compromise the integrity of the application.
Affected Version(s)
Craft CMS versions prior or equal to version 4.4.11