Cross Site Scripting Vulnerability in Crafter CMS by Crafter Software
CVE-2017-15686

6.1MEDIUM

Key Information:

Vendor

Craftercms

Vendor
CVE Published:
27 November 2020

What is CVE-2017-15686?

Crafter Studio 3.0.1 suffers from a cross-site scripting (XSS) vulnerability that can be exploited by remote attackers to steal users’ cookies. This exposes sensitive user data and poses significant security risks to web application integrity. Proper sanitization and validation of user input is essential to mitigate this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.