Impact
Craft CMS versions from 5.0.0‑RC1 through 5.10.10 allow attackers to inject malicious JavaScript into the site name field. The unsanitized value is stored and then rendered in control panel settings pages, resulting in a stored XSS vulnerability. When an authenticated user opens the affected page, the injected script executes in that user’s browser, potentially leading to session hijacking, credential theft, or defacement.
Affected Systems
The vulnerability affects all installations of Craft CMS prior to version 5.10.11, including early release candidate 5.0.0‑RC1. It applies to any environment running the default site name input without modification, regardless of operating system or hosting platform.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. No EPSS value is available, and the vulnerability is not listed in CISA KEV. The attack requires an administrator to submit a crafted site name, after which other users who view the control panel settings are impacted. Compromise is limited to users with access to the control panel; remote code execution is not possible.
OpenCVE Enrichment