VDB
Sign up
LOW3.7

GHSA-3wxg-w96j-8hq9

CraftCMS stored XSS in Quick Post widget error message

Quick fix

GHSA-3wxg-w96j-8hq9 — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^4.4.6

Details

### Summary The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload.

### Details Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save.

### PoC 1. Login at admin 2. Go to setting 3. Create a Section 4. On Entry page, click Edit label 5. Inject the XSS payload into the label and save 6. On the admin dashboard choose new widget -> Quick Post 7. In Quick Post, click save with blank slug; The XSS will be executed

"errors":{"title":["<script>alert('nono')</script> cannot be blank."],"slug":["Slug cannot be blank."]

Fixed in https://github.com/craftcms/cms/commit/9d0cd0bda7c8a830a3373f8c0f06943e519ac888

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 4.0.0-RC1Fixed in: 4.4.6
Fixcomposer require craftcms/cms:^4.4.6
Packagist/craftcms/cms
Introduced in: 3.0.0Fixed in: 3.8.6
Fixcomposer require craftcms/cms:^3.8.6

References