MEDIUM5.5
GHSA-6qjx-787v-6pxr
Craft CMS stored XSS in indexedVolumes
Quick fix
GHSA-6qjx-787v-6pxr — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^4.4.6Details
### Summary XSS can be triggered via the Update Asset Index utility
### PoC 1. Access setting tab 2. Create new assets 3. In assets name inject payload: "<script>alert(26)</script> 4. Click Utilities tab 5. Choose all volumes, or volume trigger xss 7. Click Update asset indexes.
XSS will be triggered
Json response volumes name makes triggers the payload
"session":{"id":1,"indexedVolumes":{"1":"\"<script>alert(26)</script>"},
It’s run on every POST request in the utility.
Resolved in https://github.com/craftcms/cms/commit/8c2ad0bd313015b8ee42326af2848ee748f1d766
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/craftcms/cms
Introduced in:
4.0.0-RC1Fixed in: 4.4.6Fix
composer require craftcms/cms:^4.4.6References
- https://github.com/craftcms/cms/security/advisories/GHSA-6qjx-787v-6pxr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-33197[ADVISORY]
- https://github.com/craftcms/cms/commit/8c2ad0bd313015b8ee42326af2848ee748f1d766[WEB]
- https://github.com/craftcms/cms[PACKAGE]
- https://github.com/craftcms/cms/releases/tag/4.4.6[WEB]