CVE-2022-28378: XSS
Published Apr 3, 2022
·Updated
Craft CMS before 3.7.29 allows XSS.
Affected Software
1 affected component
Craft CMS<3.7.29
Event History
Apr 3, 2022
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28378?
CVE-2022-27878 is a vulnerability in Craft CMS versions before 3.7.29 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2022-28378?
CVE-2022-28378 has a severity score of 6.1, classified as medium.
3
How does CVE-2022-28378 impact Craft CMS?
CVE-2022-28378 allows attackers to execute malicious scripts on the affected Craft CMS website, potentially leading to unauthorized access or data theft.
4
What is the affected version of Craft CMS?
Versions of Craft CMS before 3.7.29 are affected by CVE-2022-28378.
5
How can I fix CVE-2022-28378 in Craft CMS?
To fix CVE-2022-28378, it is recommended to upgrade Craft CMS to version 3.7.29 or higher, as this vulnerability has been patched in that release.