Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
Remediation
References
http://crafter.com
https://docs.craftercms.org/en/3.0/security/advisory.html
Related Vulnerabilities
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source
CVE-2018-8006 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2017-3165 Vulnerability in maven package org.apache.brooklyn:brooklyn-jsgui
CVE-2021-21348 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2018-11040 Vulnerability in maven package org.springframework:spring-web