{"id":"GHSA-mw37-wx8p-gp45","summary":"Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts","details":"Craft CMS `3.70-RC1`–`3.7.55.1` and `4.0.0-RC1`–`4.2.0.1` are vulnerable to Cross Site Scripting (XSS) via entry revisions and drafts. Versions `3.7.55.2` and `4.2.1` contain patches for this issue.","aliases":["CVE-2022-37251"],"modified":"2024-02-21T05:28:42.912868Z","published":"2022-09-17T00:00:30Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-09-20T17:14:36Z","nvd_published_at":"2022-09-16T22:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37251"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/7139213dbd9e177a3528aac8e2db8de91830f118"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/919c9074ff8596bf30a629b0888c529793e9a903"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/f0d9b8a1e3ac005a2418f7d3d9059b49a96e73ea"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"},{"type":"WEB","url":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#421---2022-08-09"},{"type":"WEB","url":"https://labs.integrity.pt/advisories/cve-2022-37251"},{"type":"WEB","url":"http://craft.com"}],"affected":[{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.7.0-beta.1"},{"fixed":"3.7.55.2"}]}],"versions":["3.7.0","3.7.0-beta.1","3.7.0-beta.2","3.7.0-beta.3","3.7.0-beta.4","3.7.0-beta.5","3.7.0-beta.6","3.7.1","3.7.10","3.7.11","3.7.12","3.7.13","3.7.14","3.7.15","3.7.16","3.7.17","3.7.17.1","3.7.17.2","3.7.18","3.7.18.1","3.7.18.2","3.7.19","3.7.19.1","3.7.2","3.7.20","3.7.21","3.7.22","3.7.23","3.7.24","3.7.25","3.7.25.1","3.7.26","3.7.27","3.7.27.1","3.7.27.2","3.7.28","3.7.29","3.7.3","3.7.3.1","3.7.3.2","3.7.30","3.7.30.1","3.7.31","3.7.32","3.7.33","3.7.34","3.7.35","3.7.36","3.7.37","3.7.38","3.7.39","3.7.4","3.7.40","3.7.40.1","3.7.41","3.7.42","3.7.43","3.7.44","3.7.45","3.7.45.1","3.7.45.2","3.7.46","3.7.47","3.7.47.1","3.7.48","3.7.49","3.7.5","3.7.50","3.7.51","3.7.52","3.7.53","3.7.53.1","3.7.54","3.7.55","3.7.55.1","3.7.6","3.7.7","3.7.8","3.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-mw37-wx8p-gp45/GHSA-mw37-wx8p-gp45.json"}},{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0-RC1"},{"fixed":"4.2.1"}]}],"versions":["4.0.0","4.0.0-RC1","4.0.0-RC2","4.0.0-RC3","4.0.0.1","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.5.1","4.0.5.2","4.0.6","4.1.0","4.1.0.1","4.1.0.2","4.1.1","4.1.2","4.1.3","4.1.4","4.1.4.1","4.2.0","4.2.0.1","4.2.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-mw37-wx8p-gp45/GHSA-mw37-wx8p-gp45.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}