Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
Remediation
References
https://docs.craftercms.org/en/3.0/security/advisory.html
http://crafter.com
Related Vulnerabilities
CVE-2022-29567 Vulnerability in maven package com.vaadin:vaadin-grid-flow
CVE-2013-4517 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2019-11272 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2022-45399 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2023-50422 Vulnerability in maven package com.sap.cloud.security:spring-security