Description
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Remediation
References
Related Vulnerabilities
XWikiplatform Improper Encoding or Escaping of Output Vulnerability (CVE-2024-55663)
WordPress Other Vulnerability (CVE-2006-0733)
Joomla! Core 2.5.x Clickjacking Vulnerability (2.5.0 - 2.5.7)
Joomla! Core 3.x.x Cross-Site Request Forgery (3.2.0 - 3.9.12)
WordPress Plugin Cimy User Extra Fields Arbitrary File Upload (2.3.7)