HIGH7.5
GHSA-6p78-f7h9-6838
Craft CMS Feed-Me
Quick fix
GHSA-6p78-f7h9-6838 — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^4.6.2Details
An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-36260[ADVISORY]
- https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28[WEB]
- https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28%29[WEB]
- https://github.com/craftcms/feed-me[PACKAGE]
- https://github.com/craftcms/feed-me/releases/tag/4.6.2[WEB]
- https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D[WEB]