CVE-2023-36259: XSS
Published Jan 30, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.
Affected Software
2 affected componentsFixes available
composer/superbig/craft-audit<3.0.2
3.0.2
Craft CMS<3.0.2
Remediation
Patch Available
Event History
Jan 30, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-36259?
CVE-2023-36259 is classified as a Cross Site Scripting (XSS) vulnerability that poses a significant risk to affected systems.
2
How do I fix CVE-2023-36259?
To fix CVE-2023-36259, update the Craft CMS Audit Plugin to version 3.0.2 or later.
3
What type of vulnerability is CVE-2023-36259?
CVE-2023-36259 is a Cross Site Scripting (XSS) vulnerability affecting the Craft CMS Audit Plugin.
4
Which versions are affected by CVE-2023-36259?
All versions of the Craft CMS Audit Plugin prior to version 3.0.2 are affected by CVE-2023-36259.
5
Who is affected by CVE-2023-36259?
Users of Craft CMS with the Audit Plugin installed prior to version 3.0.2 are affected by CVE-2023-36259.