CVE-2022-37251
PHP vulnerability analysis and mitigation

Overview

Craft CMS 4.2.0.1 was identified with a Cross-Site Scripting (XSS) vulnerability via Drafts functionality. The vulnerability was discovered on August 1, 2022, and publicly disclosed on September 7, 2022. This security issue was assigned CVE-2022-37251 and received a CVSSv3 Base Score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) (Integrity Labs).

Technical details

The vulnerability exists in the Draft functionality of Craft CMS. An attacker needs to create a new Entry and a Draft within the created Entry. The XSS payload can be introduced through the 'Draft name' field. The vulnerability manifests in three locations: the 'Apply draft' functionality, the 'Save draft' functionality, and the /admin/dashboard when the 'My Drafts' Widget is added after payload creation (Integrity Labs).

Impact

The vulnerability allows for stored Cross-Site Scripting attacks, which could lead to high confidentiality and integrity impacts. With a CVSSv3 score of 8.1, this indicates a significant security risk that could potentially allow attackers to execute malicious scripts in users' browsers (Integrity Labs).

Mitigation and workarounds

The vulnerability was fixed in Craft CMS version 4.2.1. Users are advised to update their Craft CMS installations to version 4.2.1 or higher to mitigate this security risk (Integrity Labs).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23622HIGH8.7
  • PHPPHP
  • alextselegidis/easyappointments
NoNoJan 15, 2026
CVE-2026-23493HIGH8.6
  • PHPPHP
  • pimcore/pimcore
NoYesJan 15, 2026
CVE-2026-23496MEDIUM5.4
  • PHPPHP
  • pimcore/web2print-tools-bundle
NoYesJan 15, 2026
CVE-2026-23495MEDIUM4.3
  • PHPPHP
  • pimcore/admin-ui-classic-bundle
NoYesJan 15, 2026
CVE-2026-23494MEDIUM4.3
  • PHPPHP
  • pimcore/pimcore
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management