ZeroHour

CVE-2021-23260

CVSS 3.1
5.4 medium
EPSS
<1%p36
Published
()
Modified
Description

Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.

Vendors
craftercms
Products
crafter cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.