Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-05-26T20:30:23.382Z

Updated: 2024-08-02T15:39:35.789Z

Reserved: 2023-05-17T22:25:50.699Z

Link: CVE-2023-33194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-05-26T21:15:20.890

Modified: 2023-06-02T18:43:36.960

Link: CVE-2023-33194

cve-icon Redhat

No data.