Description
Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
References
github.com/...ms/cms/security/advisories/GHSA-7pr4-wx9w-mqwr
github.com/...ommit/cfd6ba0e2ce1a59a02d75cae6558c4ace1ab8bd4
github.com/craftcms/cms/releases/tag/5.8.22