CVE-2021-23266: Improper Output Neutralization for Logs in Crafter Studio
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23266?
CVE-2021-23266 is a vulnerability in CrafterCMS, a content management system, that allows an anonymous user to craft a URL with text that can mislead the administrator in the log viewer.
What is the severity of CVE-2021-23266?
The severity of CVE-2021-23266 is medium with a severity value of 4.3.
How does CVE-2021-23266 affect CrafterCMS?
CVE-2021-23266 affects CrafterCMS versions 3.1 to 3.1.18.
How can an anonymous user exploit CVE-2021-23266?
An anonymous user can exploit CVE-2021-23266 by crafting a URL with text that appears in the log viewer, allowing them to mislead the administrator.
Where can I find more information about CVE-2021-23266?
You can find more information about CVE-2021-23266 in the security advisory provided by CrafterCMS: https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602