Stored Cross-Site Scripting Vulnerability in Craft CMS by Pixel & Tonic
CVE-2023-2817
5.4MEDIUM
Summary
A post-authentication stored cross-site scripting vulnerability has been identified in Craft CMS versions up to 4.4.11. This vulnerability allows an attacker to inject HTML, including script tags, into field names. When these fields are incorporated into categories or sections, the malicious scripts are executed when users access the Categories or Entries pages. This flaw poses a significant risk as it can lead to unauthorized access to sensitive information and compromise the integrity of the application.
Affected Version(s)
Craft CMS versions prior or equal to version 4.4.11
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved