Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Crafter_cms | Craftercms | 3.1.0 (including) | 3.1.13 (excluding) |