Vulnerability Description
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | >= 3.0.0, <= 3.8.3 |
Related Weaknesses (CWE)
References
- https://github.com/craftcms/cms/commit/52bd161614620edbab2d24d078ca9ebca2528442Patch
- https://github.com/craftcms/cms/security/advisories/GHSA-j4mx-98hw-6rv6PatchVendor Advisory
- https://github.com/craftcms/cms/commit/52bd161614620edbab2d24d078ca9ebca2528442Patch
- https://github.com/craftcms/cms/security/advisories/GHSA-j4mx-98hw-6rv6PatchVendor Advisory
FAQ
What is CVE-2023-31144?
CVE-2023-31144 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue i...
How severe is CVE-2023-31144?
CVE-2023-31144 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31144?
Check the references section above for vendor advisories and patch information. Affected products include: Craftcms Craft Cms.