CVE-2017-8384
EUVD-2022-341301.05.2017, 06:59
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| craftcms | craft_cms | 𝑥 ≤ 2.6.2974 |
𝑥
= Vulnerable software versions