Medium severity6.1NVD Advisory· Published Nov 27, 2020· Updated Jul 9, 2026
CVE-2017-15682
CVE-2017-15682
Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.craftercms:crafter-coreMaven | >= 3.0.0, < 3.0.1 | 3.0.1 |
Affected products
3- Crafter CMS/Crafter Studiodescription
Patches
Vulnerability mechanics
References
3- docs.craftercms.org/en/3.0/security/advisory.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-38rq-rh9w-cmw6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-15682ghsaADVISORY
News mentions
0No linked articles in our index yet.