CVE-2021-23260

Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:*

Information

Published : 2021-12-02 08:15

Updated : 2021-12-03 06:01


NVD link : CVE-2021-23260

Mitre link : CVE-2021-23260


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

craftercms

  • crafter_cms