{"id":"GHSA-wf98-vxv9-jqfv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-wf98-vxv9-jqfv","summary":"XSS Injection Vulnerability","details":"### Impact\n\nUnder some circumstances, the Feeds widget on the dashboard could have an XSS vulnerability if a malformed feed was supplied.\n\n### Patches\n\nThis has been patched in Craft 3.7.29.\n\n### References\n\n* https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#3729---2022-01-18\n\n### For more information\n\nIf you have any questions or comments about this advisory, email us at [support@craftcms.com](mailto:support@craftcms.com)\n\n----------\n\nCredits: https://github.com/noobpk\n","published":"2022-04-05T18:31:51Z","modified":"2024-12-05T05:39:55.757082Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"3.7.29"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-wf98-vxv9-jqfv"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:39:55.757082Z"}}