CVE-2021-23263: Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine
Published Dec 2, 2021
·Updated
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/, /templates/ and some of the files in /.git/ (non-binary).
Affected Software
1 affected component
CrafterCMS Crafter Cms>=3.1.0<3.1.15
Event History
Dec 2, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-23263?
CVE-2021-23263 is a vulnerability that allows unauthenticated remote attackers to read textual content via FreeMarker, including files in specific directories.
2
How does CVE-2021-23263 impact Crafter CMS?
CVE-2021-23263 affects Crafter CMS versions between 3.1.0 and 3.1.15.
3
What is the severity of CVE-2021-23263?
CVE-2021-23263 has a severity rating of 7.5 (high).
4
Which software is affected by CVE-2021-23263?
Crafter CMS versions between 3.1.0 and 3.1.15 are affected by CVE-2021-23263.
5
How can unauthenticated remote attackers exploit CVE-2021-23263?
Unauthenticated remote attackers can exploit CVE-2021-23263 by reading textual content via FreeMarker, including files in specific directories.