Description
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
Remediation
References
Related Vulnerabilities
WordPress Plugin Appointment Booking Calendar Cross-Site Scripting (1.3.18)
WordPress Plugin Elements For Elementor Local File Inclusion (2.1)
Oracle Database Server CVE-2008-2600 Vulnerability (CVE-2008-2600)
Oracle Database Server CVE-2006-0260 Vulnerability (CVE-2006-0260)
WordPress Plugin Recent Backups Arbitrary File Download (0.7)