ZeroHour

CVE-2023-33196

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p49
Published
()
Modified
Description

Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.

Vendors
craftcms
Products
craft cms
Weakness
CWE-80, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.