Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2022-31684 Vulnerability in maven package io.projectreactor.netty:reactor-netty-http
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-legacy-oldcore
CVE-2016-5019 Vulnerability in maven package org.apache.myfaces.trinidad:trinidad-impl