Security Advisory

CVE-2023-33194

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-05-26 20:30:23
Last updated 2025-01-14 19:25:11
Assigner GitHub_M
CVSS score 3.7
State PUBLISHED

Description

Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.