VDB
Sign up
MEDIUM6.1

GHSA-qpgm-gjgf-8c2x

Craft CMS XSS in RSS widget feed

Quick fix

GHSA-qpgm-gjgf-8c2x — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^4.4.6

Details

### Summary A malformed RSS feed can deliver an XSS payload

### PoC Create an RSS widget and add the domain https://blog.whitebear.vn/file/rss-xss2.rss The XSS payload will be triggered by the title in tag `<item>`

Resolved in https://github.com/craftcms/cms/commit/b77cb3023bed4f4a37c11294c4d319ff9f598e1f

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 4.3.0Fixed in: 4.4.6
Fixcomposer require craftcms/cms:^4.4.6

References