First published: Tue Jan 30 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/superbig/craft-audit | <3.0.2 | 3.0.2 |
CraftCMS Craft CMS | <3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36259 is classified as a Cross Site Scripting (XSS) vulnerability that poses a significant risk to affected systems.
To fix CVE-2023-36259, update the Craft CMS Audit Plugin to version 3.0.2 or later.
CVE-2023-36259 is a Cross Site Scripting (XSS) vulnerability affecting the Craft CMS Audit Plugin.
All versions of the Craft CMS Audit Plugin prior to version 3.0.2 are affected by CVE-2023-36259.
Users of Craft CMS with the Audit Plugin installed prior to version 3.0.2 are affected by CVE-2023-36259.