Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label
.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-37246
- https://github.com/craftcms/cms/commit/1d5fdba23c84d6d09a8a980c7b6fc52fb93b679b
- https://labs.integrity.pt/advisories/cve-2022-37246/
- https://github.com/craftcms/cms/commit/ecefe7f0afe0a6c4d1097a570cba82753d33f681
- https://github.com/advisories/GHSA-f546-v666-559x