VDB
Sign up
MEDIUM5.5

GHSA-6qjx-787v-6pxr

Craft CMS stored XSS in indexedVolumes

Quick fix

GHSA-6qjx-787v-6pxr — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^4.4.6

Details

### Summary XSS can be triggered via the Update Asset Index utility

### PoC 1. Access setting tab 2. Create new assets 3. In assets name inject payload: "<script>alert(26)</script> 4. Click Utilities tab 5. Choose all volumes, or volume trigger xss 7. Click Update asset indexes.

XSS will be triggered

Json response volumes name makes triggers the payload

"session":{"id":1,"indexedVolumes":{"1":"\"<script>alert(26)</script>"},

It’s run on every POST request in the utility.

Resolved in https://github.com/craftcms/cms/commit/8c2ad0bd313015b8ee42326af2848ee748f1d766

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 4.0.0-RC1Fixed in: 4.4.6
Fixcomposer require craftcms/cms:^4.4.6

References