Description
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2019-2753 Vulnerability (CVE-2019-2753)
WordPress Plugin Modula Image Gallery Cross-Site Scripting (2.2.4)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3738)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5321)