Impact
This vulnerability allows an attacker who owns a GitHub account to inject JavaScript into a Craft CMS issue title. When a site administrator uses the CraftSupport widget’s search function and the result list contains the poisoned issue, the script executes within the administrator’s control‑panel session. The‑site scripting weakness (CWE‑79). The consequence is that the attacker can execute arbitrary JavaScript in the context of the admin session.
Affected Systems
All installations of Craft CMS 5.0.0‑RC1 through 5.9.22 and 4.0.0‑RC1 through 4.17.15 are vulnerable. The issue was fixed in Craft CMS 4.17.16 and 5.9.23; upgrading to these or later versions removes the vulnerability.
Risk and Exploitability
The CVSS score is 7.4, indicating a high severity. The EPSS score is reported as <1%, implying low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a GitHub account and an administrator to view the issue via the CraftSupport widget; no CMS credentials are needed from the attacker. Thus the attack vector is remote, driven by user interaction, and does not depend on privileged access within the CMS.
OpenCVE Enrichment
Github GHSA