MEDIUM6.1
GHSA-m3v5-gjj9-rg24
Craft CMS vulnerable to HTML injection
Details
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/craftcms/cms
Introduced in:
0No fixed version published yet for craftcms/cms (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-33495[ADVISORY]
- https://github.com/craftcms/cms[PACKAGE]
- https://medium.com/@mondalsomnath9135/html-injection-in-craft-cms-application-e2b28f746212[WEB]
- https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/11-Client-side_Testing/03-Testing_for_HTML_Injection[WEB]