First published: Wed Sep 29 2021(Updated: )
Craft CMS before 3.7.14 allows CSV injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftcms Craft Cms | >=3.4.0<3.7.14 | |
>=3.4.0<3.7.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41824 is a vulnerability in Craft CMS before version 3.7.14 that allows CSV injection.
The severity of CVE-2021-41824 is high, with a CVSS score of 8.8.
CVE-2021-41824 affects Craft CMS versions before 3.7.14, allowing CSV injection.
To fix CVE-2021-41824, update Craft CMS to version 3.7.14 or later.
You can find more information about CVE-2021-41824 in the Craft CMS Changelog, the Craft CMS security advisories, and the official Craft CMS Twitter account.