First published: Mon May 16 2022(Updated: )
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Credit: security@craftersoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Craftercms Crafter Cms | >=3.1<3.1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23266 is a vulnerability in CrafterCMS, a content management system, that allows an anonymous user to craft a URL with text that can mislead the administrator in the log viewer.
The severity of CVE-2021-23266 is medium with a severity value of 4.3.
CVE-2021-23266 affects CrafterCMS versions 3.1 to 3.1.18.
An anonymous user can exploit CVE-2021-23266 by crafting a URL with text that appears in the log viewer, allowing them to mislead the administrator.
You can find more information about CVE-2021-23266 in the security advisory provided by CrafterCMS: https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602