Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown
CVE-2023-32679
Disclosure Date: May 19, 2023 (last updated October 08, 2023)
Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() -> _resolveTemplateInternal() -> _resolveTemplate() function, it returns directly without extension verification, so that arbitrary extension files are rendered as twig templates. When attacker with admin privileges on a DEV or an improperly configured STG or PROD environment, they can exploit this vulnerability to remote code execution. Code execution may grant the attacker access to the host operating system. This issue has been addressed in version 4.4.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-30130
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
0
Attacker Value
Unknown
CVE-2023-31144
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.
0
Attacker Value
Unknown
CVE-2023-30177
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
0
Attacker Value
Unknown
CVE-2023-23927
Disclosure Date: March 03, 2023 (last updated November 08, 2023)
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7.
0
Attacker Value
Unknown
CVE-2022-37783
Disclosure Date: December 05, 2022 (last updated October 08, 2023)
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corresponding HTML hidden field discloses the users' password hash in a masked manner, which can be decoded by using public functions of the YII framework.
0
Attacker Value
Unknown
CVE-2022-37246
Disclosure Date: September 21, 2022 (last updated October 08, 2023)
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
0
Attacker Value
Unknown
CVE-2022-37251
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
0
Attacker Value
Unknown
CVE-2022-37247
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
0
Attacker Value
Unknown
CVE-2022-37248
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
0