Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
Remediation
References
http://crafter.com
https://docs.craftercms.org/en/3.0/security/advisory.html
Related Vulnerabilities
CVE-2023-37912 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-macro-footnotes
CVE-2019-16568 Vulnerability in maven package hudson.plugins.sctmexecutor:sctmexecutor
CVE-2020-1960 Vulnerability in maven package org.apache.flink:flink-metrics-jmx
CVE-2023-27905 Vulnerability in maven package org.jenkins-ci:update-center2
CVE-2023-31469 Vulnerability in maven package org.apache.streampipes:streampipes-rest