Description
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Remediation
References
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2022051602
Related Vulnerabilities
CVE-2013-4942 Vulnerability in npm package yui
CVE-2023-35150 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2023-49800 Vulnerability in npm package nuxt-api-party
CVE-2023-24454 Vulnerability in maven package org.jenkins-ci.plugins:testquality-updater
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-html-support