CVE

CVE-2021-23266

Severity:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/05/2022
Last modified:
25/05/2022

Description

An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.

Vulnerable products and versions

  • cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:*

References to Advisories, Solutions, and Tools