CVE-2022-37247: XSS
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-37247?
CVE-2022-37247 is a vulnerability in Craft CMS 4.2.0.1 that allows for stored cross-site scripting (XSS) attacks.
What is the severity of CVE-2022-37247?
The severity of CVE-2022-37247 is medium with a CVSS score of 5.4.
How does CVE-2022-37247 affect Craft CMS 4.2.0.1?
CVE-2022-37247 affects Craft CMS 4.2.0.1 by allowing for stored cross-site scripting (XSS) attacks through the /admin/settings/fields page.
Is there a fix available for CVE-2022-37247?
Yes, a fix for CVE-2022-37247 is available. Craft CMS users should update to a patched version of the software.
Where can I find more information about CVE-2022-37247?
You can find more information about CVE-2022-37247 at the following references: [GitHub](https://github.com/craftcms/cms/commit/cedeba0609e4b173cd584dae7f33c5f713f19627) and [Integrity Labs](https://labs.integrity.pt/advisories/cve-2022-37247/).