CVE-2022-37251Cross-site Scripting in Craft CMS

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 44.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateSep 17

Description

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

Packagistcraftcms/cms3.7.0-beta.13.7.55.2+1
NVDcraftcms/craft_cms4.2.0.1

🔴Vulnerability Details

3
OSV
Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts2022-09-17
GHSA
Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts2022-09-17
CVEList
CVE-2022-37251: Craft CMS 42022-09-16
CVE-2022-37251 — Cross-site Scripting in Craft CMS | cvebase