High severity8.6NVD Advisory· Published Nov 27, 2020· Updated Jul 9, 2026
CVE-2017-15683
CVE-2017-15683
Description
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.craftercms:crafter-coreMaven | >= 3.0.0, < 3.0.1 | 3.0.1 |
Affected products
3- Crafter CMS/Crafter Studiodescription
Patches
Vulnerability mechanics
References
3- docs.craftercms.org/en/3.0/security/advisory.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-p2vm-88rg-wfr2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-15683ghsaADVISORY
News mentions
0No linked articles in our index yet.