Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2018-8006 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2018-8024 Vulnerability in maven package org.apache.spark:spark-core
CVE-2019-10392 Vulnerability in maven package org.jenkins-ci.plugins:git-client
CVE-2020-1725 Vulnerability in maven package org.keycloak:keycloak-core