CVE-2021-23263

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/12/2021
Last modified:
30/08/2022

Description

Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.15 (excluding)