VDB
Sign up
MEDIUM6.1

GHSA-qcrj-6ffc-v7hq

Craft CMS Stored Cross-site Scripting Injection Vulnerability

Quick fix

GHSA-qcrj-6ffc-v7hq — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^4.3.7

Details

### Summary _When you insert a payload inside a label name or instruction of an entry type, an XSS happens in the quick post widget on the admin dashboard._

### PoC [_Complete instructions, including specific configuration details, to reproduce the vulnerability._](https://user-images.githubusercontent.com/53917092/215604129-d5b75608-5a24-4eb3-906f-55b192310298.mp4)

### Impact Tested with the free version of Craft CMS 4.3.6.1

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 4.0.0-RC1Fixed in: 4.3.7
Fixcomposer require craftcms/cms:^4.3.7
Packagist/craftcms/cms
Introduced in: 3.7.24Fixed in: 3.7.64
Fixcomposer require craftcms/cms:^3.7.64

References