Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
Remediation
References
http://crafter.com
https://docs.craftercms.org/en/3.0/security/advisory.html
Related Vulnerabilities
CVE-2022-39202 Vulnerability in npm package matrix-appservice-irc
CVE-2014-0099 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2022-41930 Vulnerability in maven package org.xwiki.platform:xwiki-platform-user-profile-ui
CVE-2019-10385 Vulnerability in maven package org.jenkins-ci.plugins:eggplant-plugin
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js