Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Crafter_cms | Craftercms | 3.1.0 (including) | 3.1.15 (excluding) |