GHSA-3wxg-w96j-8hq9
CraftCMS stored XSS in Quick Post widget error message
Quick fix
GHSA-3wxg-w96j-8hq9 — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^4.4.6Details
### Summary The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload.
### Details Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save.
### PoC 1. Login at admin 2. Go to setting 3. Create a Section 4. On Entry page, click Edit label 5. Inject the XSS payload into the label and save 6. On the admin dashboard choose new widget -> Quick Post 7. In Quick Post, click save with blank slug; The XSS will be executed
"errors":{"title":["<script>alert('nono')</script> cannot be blank."],"slug":["Slug cannot be blank."]
Fixed in https://github.com/craftcms/cms/commit/9d0cd0bda7c8a830a3373f8c0f06943e519ac888
Are you affected?
Enter the version of the package you're using.
Affected packages
4.0.0-RC1Fixed in: 4.4.6composer require craftcms/cms:^4.4.6References
- https://github.com/craftcms/cms/security/advisories/GHSA-3wxg-w96j-8hq9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-33194[ADVISORY]
- https://github.com/craftcms/cms/commit/9d0cd0bda7c8a830a3373f8c0f06943e519ac888[WEB]
- https://github.com/craftcms/cms[PACKAGE]
- https://github.com/craftcms/cms/releases/tag/4.4.6[WEB]