CVE-2019-9554

MEDIUM WAF: High
CVSS 6.1 Published: 2019-12-31
CWE-79

In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
craftcmscraft_cms3.1.12

References

Back to CVE Database