Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2021120103 | vendor advisory |