Impact
The flaw allows a content editor to store malicious JavaScript in editable fields that are rendered by the Control Panel’s element indexes. Because the Generated Fields feature disables Twig auto‑escaping and does not encode cached values, the attacker’s code is executed in the browsers of authenticated, higher‑privileged users. This stored XSS (CWE‑79) can disclose session information, deface content, or enable further attacks within the application. The exploit requires only that an editor create or edit a field containing script payloads; no additional network access or external injection is needed.
Affected Systems
The defect exists in Craft CMS from version 5.7.0 up to, but not including, 5.10.13. Users running any of these vulnerable versions, especially those with editing or administrative privileges in the Control Panel, are impacted.
Risk and Exploitability
The CVSS score of 5.1 denotes a medium severity vulnerability, and the EPSS score is below 1 %, indicating a low probability of automated exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can typically exploit the flaw by logging as a content editor, entering a crafted payload into a generated field, and then having a higher‑privileged Control Panel user view the element index. The code runs in the browser of the viewing user, allowing for cookie theft, UI manipulation, or masquerading as legitimate application scripts. No advanced prerequisites beyond valid credentials are required.
OpenCVE Enrichment