CVE-2023-2817Cross-site Scripting in Craft CMS

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 57.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26

Description

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

Packagistcraftcms/cms4.0.0-RC14.4.12
NVDcraftcms/craft_cms4.4.11
CVEListV5craftcms/craft_cmsversions prior or equal to version 4.4.11

Patches

🔴Vulnerability Details

3
CVEList
CVE-2023-2817: A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 42023-05-26
OSV
Stored cross site scripting in Craft CMS2023-05-26
GHSA
Stored cross site scripting in Craft CMS2023-05-26
CVE-2023-2817 — Cross-site Scripting in Craft CMS | cvebase