CVE-2017-8384
01.05.2017, 06:59
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Vendor | Product | Version |
---|---|---|
craftcms | craft_cms | 𝑥 ≤ 2.6.2974 |
𝑥
= Vulnerable software versions