A stored Cross-site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another user, would execute in their browser.
Consumers are affected if ALL of these are true:
Payload version < v3.78.0
At least one collection with versions enabled
An authenticated user has create or update access to that collection
Patches
This vulnerability has been patched in v3.78.0. Output encoding has been added to prevent user-supplied content from being interpreted as markup.
Users should upgrade to v3.78.0 or later.
Workarounds
If consumers cannot upgrade immediately:
Restrict create and update access to versioned collections to trusted roles only.