VYPR
Medium severity5.4NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026

CVE-2023-2817

CVE-2023-2817

Description

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
craftcms/cmsPackagist
>= 4.0.0-RC1, < 4.4.124.4.12

Affected products

3
  • cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*range: <=4.4.11
    • (no CPE)range: versions prior or equal to version 4.4.11
  • ghsa-coords
    Range: >= 4.0.0-RC1, < 4.4.12

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.