First published: Fri Nov 27 2020(Updated: )
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftercms Crafter Cms | >=3.0.0<3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-15682.
The affected software for this vulnerability is Crafter CMS Crafter Studio 3.0.1.
The severity of CVE-2017-15682 is medium.
An unauthenticated attacker can exploit CVE-2017-15682 by injecting malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
You can find more information about this vulnerability on the Crafter CMS website and the official security advisory.