OSV 1.4.0 · github-reviewed · 修改于 2021-04-14 01:51
发布时间
2022-02-10 07:08
GitHub 审查时间
2021-04-14 01:51
NVD 发布时间
2020-11-28 02:15
源文件
advisories/github-reviewed/2022/02/GHSA-5hr6-vc97-qxxh/GHSA-5hr6-vc97-qxxh.json
Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.