CVE-2021-23260

Publication date

2021-12-02 15:40:56

Family

crafter

State

PUBLISHED

Description

Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.