MEDIUM
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS
Published Jun 18, 2019
6.1
MEDIUMCVSS 3.1
EPSS 0.94%
Description
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5504 Advisory
- https://github.com/advisories/GHSA-w5q4-q7wp-qww6 Advisory
- https://github.com/craftcms/cms/blob/6432eca59b93bcea2ca2616199e5d419447e613f/CHANGELOG-v3.md
- https://github.com/craftcms/cms/blob/master/CHANGELOG-v3.md x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/craftcms/cms/commit/6432eca59b93bcea2ca2616199e5d419447e613f x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-12823
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5504 | Advisory | |
| https://github.com/advisories/GHSA-w5q4-q7wp-qww6 | Advisory | |
| https://github.com/craftcms/cms/blob/6432eca59b93bcea2ca2616199e5d419447e613f/CHANGELOG-v3.md | ||
| https://github.com/craftcms/cms/blob/master/CHANGELOG-v3.md | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/craftcms/cms/commit/6432eca59b93bcea2ca2616199e5d419447e613f | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-12823 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 18, 2019
Updated Aug 4, 2024
Reserved Jun 14, 2019
Link CVE-2019-12823
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-5504 GHSA-W5Q4-Q7WP-QWW6 Assigner mitre
Published Jun 18, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-5504