MEDIUM6.1
GHSA-qcrj-6ffc-v7hq
Craft CMS Stored Cross-site Scripting Injection Vulnerability
Quick fix
GHSA-qcrj-6ffc-v7hq — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^4.3.7Details
### Summary _When you insert a payload inside a label name or instruction of an entry type, an XSS happens in the quick post widget on the admin dashboard._
### PoC [_Complete instructions, including specific configuration details, to reproduce the vulnerability._](https://user-images.githubusercontent.com/53917092/215604129-d5b75608-5a24-4eb3-906f-55b192310298.mp4)
### Impact Tested with the free version of Craft CMS 4.3.6.1
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/craftcms/cms
Introduced in:
4.0.0-RC1Fixed in: 4.3.7Fix
composer require craftcms/cms:^4.3.7References
- https://github.com/craftcms/cms/security/advisories/GHSA-qcrj-6ffc-v7hq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-23927[ADVISORY]
- https://github.com/craftcms/cms[PACKAGE]
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#437---2023-02-03[WEB]
- https://user-images.githubusercontent.com/53917092/215604129-d5b75608-5a24-4eb3-906f-55b192310298.mp4[WEB]