Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
Remediation
References
http://crafter.com
https://docs.craftercms.org/en/3.0/security/advisory.html
Related Vulnerabilities
CVE-2022-24785 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2022-36921 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2023-25767 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials
CVE-2017-15685 Vulnerability in maven package org.craftercms:crafter-studio
CVE-2020-9489 Vulnerability in maven package org.apache.tika:tika-parsers