Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.
History

Tue, 14 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-14T19:25:11.922Z

Reserved: 2023-05-17T22:25:50.699Z

Link: CVE-2023-33194

cve-icon Vulnrichment

Updated: 2024-08-02T15:39:35.789Z

cve-icon NVD

Status : Modified

Published: 2023-05-26T21:15:20.890

Modified: 2024-11-21T08:05:05.833

Link: CVE-2023-33194

cve-icon Redhat

No data.