MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2021-23263

CVSS 5.9v3.1pub. 2021-12-02upd. 2024-11-21

Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Craftercms Crafter Cms

    APP
    Craftercms
    3.1.0 – 3.1.15 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2017-15681CRITICAL9.8PL ✓same product

Path Traversal w Crafter CMS Studio umożliwiający RCE bez uwierzytelnienia

CVE-2021-23267HIGH7.6same product

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows a...

CVE-2021-23264HIGH8.1same product

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, ...

CVE-2017-15685HIGH8.6same product

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is abl...

CVE-2017-15684HIGH7.5same product

Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attacker...