Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2018-1114 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-29516 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-ui
CVE-2019-12419 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-sso-oidc
CVE-2017-1000356 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10436 Vulnerability in maven package org.jenkins-ci.plugins:google-oauth-plugin