CVE-2023-31144: Craft CMS vulnerable to cross site scripting in RSS feed widget
A malformed title in the feed widget of craftcms/cms can deliver an XSS payload. This has been resolved in this commit.
Other sources
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Craft CMS issue?
The vulnerability ID for this Craft CMS issue is CVE-2023-31144.
What is the severity level of CVE-2023-31144?
The severity level of CVE-2023-31144 is medium.
How can CVE-2023-31144 be exploited?
CVE-2023-31144 can be exploited by delivering a cross-site scripting payload through a malformed title in the feed widget of Craft CMS.
Which versions of Craft CMS are affected by CVE-2023-31144?
Versions 3.0.0 to 3.8.3 and versions 4.0.0 to 4.4.3 of Craft CMS are affected by CVE-2023-31144.
How can I fix CVE-2023-31144?
To fix CVE-2023-31144, you need to update Craft CMS to version 3.8.4 or 4.4.4.