Description CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name. Remediation References CVE-2023-30177 Related Vulnerabilities Collabtive Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4269) WordPress Plugin WordPress Download Manager Directory Traversal (2.6.95) Chamilo Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2025-50194) MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2023-45363) Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1155) Severity Medium Classification CVE-2023-30177 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities