CVE-2023-30177: XSS
Published Apr 25, 2023
·Updated
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
Other sources
CraftCMS prior to version 3.7.68 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<3.7.68
3.7.68
Craft CMS=3.7.59
Remediation
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is the vulnerability ID of this CraftCMS vulnerability?
The vulnerability ID is CVE-2023-30177.
2
What is the severity of CVE-2023-30177?
The severity of CVE-2023-30177 is medium.
3
How does CVE-2023-30177 affect CraftCMS?
CVE-2023-30177 affects CraftCMS versions prior to 3.7.68.
4
What is the impact of CVE-2023-30177?
The impact of CVE-2023-30177 is Cross-Site Scripting (XSS), allowing an attacker to inject JavaScript code into the Volume Name field.
5
How can I fix CVE-2023-30177?
To fix CVE-2023-30177, upgrade CraftCMS to version 3.7.68 or later.