Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2023-46651 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2023-45807 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2013-3827 Vulnerability in maven package com.sun.faces:jsf-impl
CVE-2018-1271 Vulnerability in maven package org.springframework:spring-webmvc