CVE-2020-25802
06.10.2020, 14:15
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.Enginsight
Vendor | Product | Version |
---|---|---|
craftercms | studio | 3.0.0 ≤ 𝑥 < 3.0.27 |
craftercms | studio | 3.1.0 ≤ 𝑥 < 3.1.7 |
𝑥
= Vulnerable software versions