THREAT OPS › Threat News › [GHSA] GHSA-2rp4-x2j7-qmcc (medium) — Craft CMS: Stored XSS in the control panel via unescaped draft name
[GHSA] GHSA-2rp4-x2j7-qmcc (medium) — Craft CMS: Stored XSS in the control panel via unescaped draft name
GHSA-2rp4-x2j7-qmcc Severity: medium CVE: None
Craft CMS: Stored XSS in the control panel via unescaped draft name
The control-panel helper that renders element chip/card labels writes an element's `draftName` into the page without HTML-encoding it, while the surrounding path segments are encoded.
A low-privilege control-panel user who can create a draft of an element (for example, an entry) co
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-2rp4-x2j7-qmcc