craftcms/cms vulnerable to cross site scripting in RSS feed widget
Package
Affected versions
>= 3.0.0, <= 3.8.3
>= 4.0.0, <= 4.4.3
Patched versions
3.8.4
4.4.4
Description
Published to the GitHub Advisory Database
May 5, 2023
Reviewed
May 5, 2023
Published by the National Vulnerability Database
May 9, 2023
Last updated
Nov 7, 2023
A malformed title in the feed widget of craftcms/cms can deliver an XSS payload. This has been resolved in this commit.
References