CVE-2022-37248: XSS
Published Sep 16, 2022
·Updated
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
Affected Software
1 affected component
Craft CMS=4.2.0.1
Remediation
Patch Available
Event History
Sep 16, 2022
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-37248?
The severity of CVE-2022-37248 is medium with a severity value of 5.4.
2
How does CVE-2022-37248 affect Craft CMS 4.2.0.1?
CVE-2022-37248 affects Craft CMS 4.2.0.1 by allowing Cross-Site Scripting (XSS) attacks through the src/helpers/Cp.php file.
3
Is Craft CMS 4.2.0.1 the only affected version?
Yes, Craft CMS 4.2.0.1 is the only affected version.
4
How can I fix CVE-2022-37248?
To fix CVE-2022-37248, update Craft CMS to a version that includes the patch provided by Craft CMS. Refer to the official Craft CMS documentation for the latest updates.
5
Where can I find more information about CVE-2022-37248?
You can find more information about CVE-2022-37248 on the GitHub commit and the advisory published by Integrity.