CVE-2022-37246: XSS
Published Sep 21, 2022
·Updated
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
Affected Software
1 affected component
Craft CMS=4.2.0.1
Remediation
Patch Available
Event History
Sep 21, 2022
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-37246.
2
What is the severity of CVE-2022-37246?
The severity of CVE-2022-37246 is medium with a severity value of 5.4.
3
What software versions are affected by CVE-2022-37246?
Craft CMS 4.2.0.1 is affected by CVE-2022-37246.
4
How does CVE-2022-37246 affect Craft CMS?
CVE-2022-37246 affects Craft CMS by allowing Cross Site Scripting (XSS) attacks through a specific file in the source code.
5
How can I fix CVE-2022-37246?
To fix CVE-2022-37246, update to a version of Craft CMS that includes the patch mentioned in the provided reference links.