craftcms/cms is vulnerable to Cross-Site Scripting (XSS)
35
Low Risk
Craft CMS renders an element's draft name in control-panel chip and card labels without HTML-encoding it, while the surrounding path segments are encoded. A low-privilege author who can create a draft controls the draft name and can store a script payload that runs when another control-panel user is shown that element's chip or card. The payload executes in the victim's authenticated control-panel origin and can read the CSRF token and issue actions as that user, including higher-privileged accounts. The fix HTML-encodes the draft name before output.
You are affected if you are using a version that falls within the vulnerable range and you grant control-panel access to users who can create element drafts.
craftcms/cms is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 5.10.7.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant