Description
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 4.6.2
Credits
Thank you to [Rozza / rchar](https://gitlab.com/rchar) on GitLab for reporting this issue.
References
gitlab.com/crafty-controller/crafty-4/-/issues/647 (GitLab Issue #647)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.