VYPR
Medium severity6.1NVD Advisory· Published Nov 27, 2020· Updated Jul 9, 2026

CVE-2017-15682

CVE-2017-15682

Description

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.craftercms:crafter-coreMaven
>= 3.0.0, < 3.0.13.0.1

Affected products

3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.