Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
References
Link | Resource |
---|---|
https://github.com/craftcms/cms/commit/8c2ad0bd313015b8ee42326af2848ee748f1d766 | Patch |
https://github.com/craftcms/cms/releases/tag/4.4.6 | Release Notes |
https://github.com/craftcms/cms/security/advisories/GHSA-6qjx-787v-6pxr | Exploit Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-05-26 20:15
Updated : 2023-06-01 14:02
NVD link : CVE-2023-33197
Mitre link : CVE-2023-33197
CVE.ORG link : CVE-2023-33197
JSON object : View
Products Affected
craftcms
- craft_cms