Description
Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
Remediation
References
http://crafter.com
https://docs.craftercms.org/en/3.0/security/advisory.html
Related Vulnerabilities
CVE-2020-11990 Vulnerability in npm package cordova-plugin-camera
CVE-2015-5346 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-6459 Vulnerability in npm package electron
CVE-2014-0230 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2016-2402 Vulnerability in maven package com.squareup.okhttp3:okhttp