Description
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
Remediation
References
Related Vulnerabilities
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-15098)
WordPress Plugin Custom Text Selection Colors Cross-Site Scripting (1.0)
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3514)