CVE-2022-37246 | Craft CMS 4.2.0.1 BaseElementSelectInput.js elementInfo.label cross site scripting
A vulnerability was found in Craft CMS 4.2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src/web/assets/cp/src/js/BaseElementSelectInput.js. The manipulation of the argument elementInfo.label leads to cross site scripting.
This vulnerability is known as CVE-2022-37246. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.