Incomplete Fix for XSS Vulnerability in Craft CMS

Incomplete Fix for XSS Vulnerability in Craft CMS

CVE-2017-8384 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.

Learn more about our Cms Pen Testing.