CVE-2023-33197 Information
May 27, 2023
cve
Description
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
Reference
https://github.com/craftcms/cms/releases/tag/4.4.6 https://github.com/craftcms/cms/commit/8c2ad0bd313015b8ee42326af2848ee748f1d766 https://github.com/craftcms/cms/security/advisories/GHSA-6qjx-787v-6pxr
Share on: