Incomplete Fix for XSS Vulnerability in Craft CMS
CVE-2017-8384 · MEDIUM Severity
AV:N/AC:M/AU:N/C:N/I:P/A:N
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Learn more about our Cms Pen Testing.