Description
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
Remediation
References
Related Vulnerabilities
Grafana Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-10452)
Ruby Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31810)
WordPress Plugin teachPress Unspecified Vulnerability (5.0.17)
WordPress Plugin Matrix Gallery 'upload.php' Arbitrary File Upload (2.1)
WordPress Plugin Membership 2 Unspecified Vulnerability (4.0.0.2)