VDB
Sign up
HIGH7.5

GHSA-6p78-f7h9-6838

Craft CMS Feed-Me

Quick fix

GHSA-6p78-f7h9-6838 — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^4.6.2

Details

An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 0Fixed in: 4.6.2
Fixcomposer require craftcms/cms:^4.6.2

References