Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
Remediation
References
https://docs.craftercms.org/en/3.0/security/advisory.html
http://crafter.com
Related Vulnerabilities
CVE-2023-29206 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx
CVE-2023-25158 Vulnerability in maven package org.geotools:gt-jdbc
CVE-2021-22060 Vulnerability in maven package org.springframework:spring-core
CVE-2016-3725 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2229 Vulnerability in maven package org.jenkins-ci.main:jenkins-core