Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2011-3375 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2019-10080 Vulnerability in maven package org.apache.nifi:nifi-lookup-services
CVE-2023-25767 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials
CVE-2016-1202 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-37913 Vulnerability in maven package org.xwiki.platform:xwiki-platform-office-importer