Total vulnerabilities in the database
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Software | From | Fixed in |
---|---|---|
craftcms / craft_cms | - | 2.6.2974.x |