Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2019-1003054 Vulnerability in maven package info.bluefloyd.jenkins:jenkins-jira-issue-updater
CVE-2023-25806 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2023-49800 Vulnerability in npm package nuxt-api-party
CVE-2017-7545 Vulnerability in maven package org.jbpm:jbpm-designer-backend
CVE-2014-3603 Vulnerability in maven package org.opensaml:opensaml