Description Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. Remediation References CVE-2017-8383 Related Vulnerabilities PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2094) WordPress Plugin Events Manager Cross-Site Scripting (5.8.1.3) TYPO3 Improper Input Validation Vulnerability (CVE-2010-4068) Oracle Database Server Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2006-1868) PHP Other Vulnerability (CVE-2006-4625) Severity Medium Classification CVE-2017-8383 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Tags Missing Update Known Vulnerabilities