Intel

AIKIDO-2024-10123

craftcms/cms is vulnerable to Cross-Site Scripting

Cross-Site ScriptingCVE-2024-45406 Published Jun 7, 2024

50

Medium Risk

This Affects:

phpcraftcms/cms
5.0.0 - 5.1.1
Fixed in 5.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of craftcms/cms are vulnerable to Cross-site Scripting (XSS) via UI labels of elements.

Who does this affect?

You are affected if you use a vulnerable version of craftcms/cms. The patch of the vulnerability can be reviewed at: https://github.com/craftcms/cms/commit/b7348942f8131b3868ec6f46d615baae50151bb8.

Background info

craftcms/cms is vulnerable to Cross-Site Scripting in versions 5.0.0 - 5.1.1.

How to fix this

Upgrade craftcms/cms to the patch version (5.1.2).