HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2017-15685

CVSS 8.6v3.1pub. 2020-11-27upd. 2026-07-09

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  • Craftercms Crafter Cms

    APP
    Craftercms
    3.0.0 – 3.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassXXE
CWE
References

Related vulnerabilities

CVE-2017-15681CRITICAL9.8PL ✓same product

Path Traversal w Crafter CMS Studio umożliwiający RCE bez uwierzytelnienia

CVE-2021-23267HIGH7.6same product

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows a...

CVE-2021-23264HIGH8.1same product

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, ...

CVE-2017-15684HIGH7.5same product

Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attacker...

CVE-2017-15683HIGH8.6same product

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafte...