Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/craftcms/cms/security/advisories/GHSA-28h4-788g-rh42 | vendor advisory exploit |
https://github.com/craftcms/cms/commit/b7348942f8131b3868ec6f46d615baae50151bb8 | patch |