Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2023-25813 Vulnerability in npm package sequelize
CVE-2018-25007 Vulnerability in maven package com.vaadin:flow-server
CVE-2019-10398 Vulnerability in maven package org.jenkins-ci.plugins:beaker-builder
CVE-2020-2246 Vulnerability in maven package org.jenkins-ci.plugins:valgrind
CVE-2012-5885 Vulnerability in maven package org.apache.tomcat:tomcat-catalina