Skip to content

XSS Injection Vulnerability

Low
angrybrad published GHSA-wf98-vxv9-jqfv Apr 4, 2022

Package

craftcms/cms (PHP)

Affected versions

< 3.7.29

Patched versions

3.7.29

Description

Impact

Under some circumstances, the Feeds widget on the dashboard could have an XSS vulnerability if a malformed feed was supplied.

Patches

This has been patched in Craft 3.7.29.

References

For more information

If you have any questions or comments about this advisory, email us at support@craftcms.com


Credits: https://github.com/noobpk

Severity

Low

CVE ID

CVE-2022-28378

Weaknesses

No CWEs