CVE-2021-23266

MEDIUM4.3EPSS 0.24%

Log value insertion in craftercms

Published: 5/17/2022Modified: 11/8/2023
Also known as:GHSA-545f-pgp7-fwjf

Description

An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References (2)