Описание
Log value insertion in craftercms
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Пакеты
Наименование
org.craftercms:craftercms
maven
Затронутые версииВерсия исправления
>= 3.1.0, < 3.1.18
3.1.18
Связанные уязвимости
CVSS3: 4.3
nvd
больше 3 лет назад
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.