Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2014-3656 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2022-29166 Vulnerability in npm package matrix-appservice-irc
CVE-2020-16041 Vulnerability in maven package org.webjars.npm:electron
CVE-2014-3600 Vulnerability in maven package org.apache.activemq:apache-activemq
CVE-2009-0783 Vulnerability in maven package org.apache.tomcat:catalina