CVE-2023-2817 is a post-authentication stored cross-site scripting (XSS) vulnerability affecting Craft CMS versions 4.4.11 and earlier. An authenticated attacker can inject malicious HTML, including script tags, into field names. This malicious code executes when other users view the Categories or Entries pages where the compromised field is displayed. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack with low privileges required and user interaction. Successful exploitation could lead to limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4.11CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Stored cross site scripting in Craft CMS
May 26, 2023Stored Cross-Site Scripting in Craft CMS
May 19, 2023Stored Cross-Site Scripting in Craft CMS
May 19, 2023Stored Cross-Site Scripting in Craft CMS
May 19, 2023Stored Cross-Site Scripting in Craft CMS
May 19, 2023