Description
Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
Remediation
References
http://crafter.com
https://docs.craftercms.org/en/3.0/security/advisory.html
Related Vulnerabilities
CVE-2020-2199 Vulnerability in maven package org.jenkins-ci.plugins:subversion
CVE-2022-41233 Vulnerability in maven package org.jenkins-ci.plugins:rundeck
CVE-2023-24443 Vulnerability in maven package org.jenkins-ci.plugins:testcomplete
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-csrf-reactive
CVE-2023-34047 Vulnerability in maven package org.springframework.graphql:spring-graphql