{"id":"GHSA-4m2g-668v-jwjx","summary":"Cross site scripting in getkirby/starterkit","details":"A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.","aliases":["CVE-2022-35174"],"modified":"2024-02-22T05:28:08.126558Z","published":"2022-08-19T00:00:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-08-30T20:33:35Z","nvd_published_at":"2022-08-18T18:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35174"},{"type":"PACKAGE","url":"https://github.com/getkirby/starterkit"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/xss"},{"type":"WEB","url":"https://www.youtube.com/watch?v=0lngc_zPTSg"}],"affected":[{"package":{"name":"getkirby/starterkit","ecosystem":"Packagist","purl":"pkg:composer/getkirby/starterkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.7.0.2"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.4.0","3.4.1","3.4.2","3.4.3","3.4.4","3.4.5","3.5.0","3.5.1","3.5.2","3.5.3","3.5.3.1","3.5.4","3.5.5","3.5.6","3.5.7","3.5.7.1","3.5.8","3.6.0","3.6.1","3.6.1.1","3.6.2","3.6.3","3.6.3.1","3.6.4","3.6.5","3.6.6","3.7.0","3.7.0.1","3.7.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-4m2g-668v-jwjx/GHSA-4m2g-668v-jwjx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}