Description
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1487 | Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6. |
Github GHSA |
GHSA-6qjx-787v-6pxr | Craft CMS stored XSS in indexedVolumes |
References
History
Tue, 14 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-14T19:32:21.443Z
Reserved: 2023-05-17T22:25:50.699Z
Link: CVE-2023-33197
Updated: 2024-08-02T15:39:35.782Z
Status : Modified
Published: 2023-05-26T20:15:48.600
Modified: 2024-11-21T08:05:06.290
Link: CVE-2023-33197
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA