CVE List

CVE-2021-23262

Critical 7.2

Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

Published December 2, 2021.

Affected software

Get alerts for Craftercms Crafter CMS

Reference links