CVE-2021-23260
EUVD-2021-1035902.12.2021, 16:15
Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| craftercms | crafter_cms | 3.1.0 ≤ 𝑥 < 3.1.12 |
𝑥
= Vulnerable software versions