
Cloud Vulnerability DB
A community-led vulnerabilities database
Craft CMS 4.2.0.1 was identified with a Cross-Site Scripting (XSS) vulnerability via Drafts functionality. The vulnerability was discovered on August 1, 2022, and publicly disclosed on September 7, 2022. This security issue was assigned CVE-2022-37251 and received a CVSSv3 Base Score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) (Integrity Labs).
The vulnerability exists in the Draft functionality of Craft CMS. An attacker needs to create a new Entry and a Draft within the created Entry. The XSS payload can be introduced through the 'Draft name' field. The vulnerability manifests in three locations: the 'Apply draft' functionality, the 'Save draft' functionality, and the /admin/dashboard when the 'My Drafts' Widget is added after payload creation (Integrity Labs).
The vulnerability allows for stored Cross-Site Scripting attacks, which could lead to high confidentiality and integrity impacts. With a CVSSv3 score of 8.1, this indicates a significant security risk that could potentially allow attackers to execute malicious scripts in users' browsers (Integrity Labs).
The vulnerability was fixed in Craft CMS version 4.2.1. Users are advised to update their Craft CMS installations to version 4.2.1 or higher to mitigate this security risk (Integrity Labs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."