vendor:
Craft CMS
by:
Ismail Tasdelen
6.1
CVSS
MEDIUM
Cross-site Scripting
CWE
Product Name: Craft CMS
Affected Version From: 3.1.12 Pro
Affected Version To: 3.1.12 Pro
Patch Exists: NO
Related CWE: CVE-2019-9554
CPE:
Platforms Tested:
2019
Craft CMS 3.1.12 Pro – Cross-Site Scripting
In the 3.1.12 Pro version of the Craft CMS web application, the XSS vulnerability has been discovered in the header insertion field when adding source code.