CVE-2022-37251: XSS
Published Sep 16, 2022
·Updated
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
Affected Software
1 affected component
Craft CMS=4.2.0.1
Event History
Sep 16, 2022
CVE Published
via MITRE·08:54 PM
Data Sourced
via MITRE·08:54 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability CVE-2022-37251?
CVE-2022-37251 is a Cross Site Scripting (XSS) vulnerability in Craft CMS 4.2.0.1 via Drafts.
2
How severe is the vulnerability CVE-2022-37251?
The severity of CVE-2022-37251 is medium with a CVSS score of 5.4.
3
How can I fix the vulnerability CVE-2022-37251?
To fix the vulnerability CVE-2022-37251, it is recommended to upgrade to a version of Craft CMS that is not affected by this vulnerability.
4
What is Cross Site Scripting (XSS)?
Cross Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
5
What is Craft CMS?
Craft CMS is a content management system (CMS) used for building websites and web applications.