Description
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qcrj-6ffc-v7hq | Craft CMS Stored Cross-site Scripting Injection Vulnerability |
References
History
Tue, 25 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T15:02:32.273Z
Reserved: 2023-01-19T21:12:31.359Z
Link: CVE-2023-23927
Updated: 2024-08-02T10:42:26.816Z
Status : Modified
Published: 2023-03-03T22:15:09.750
Modified: 2024-11-21T07:47:07.033
Link: CVE-2023-23927
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA