First published: Wed Sep 21 2022(Updated: )
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftcms Craft Cms | =4.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-37246.
The severity of CVE-2022-37246 is medium with a severity value of 5.4.
Craft CMS 4.2.0.1 is affected by CVE-2022-37246.
CVE-2022-37246 affects Craft CMS by allowing Cross Site Scripting (XSS) attacks through a specific file in the source code.
To fix CVE-2022-37246, update to a version of Craft CMS that includes the patch mentioned in the provided reference links.