-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unescaped output of user-controlled data in two methods:
The GitHub patch (cedeba0) explicitly adds Html::encode() wrappers around these values, confirming these were the XSS injection points. The vulnerability documentation specifically references Cp.php as the source, and the commit message 'More XSS vulnerabilities' indicates these were the vulnerable functions.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| craftcms/cms | composer | >= 4.0.0-RC1, < 4.2.1 | 4.2.1 |
KEV Misses 88% of Exploited CVEs- Get the report