Описание
Craft CMS XSS Vulnerability
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Пакеты
Наименование
craftcms/cms
composer
Затронутые версииВерсия исправления
< 2.6.2976
2.6.2976
Связанные уязвимости
CVSS3: 6.1
nvd
почти 9 лет назад
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.