Описание
VaahCMS is vulnerable to XSS through its Avatar Upload endpoint
Cross-Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php
Пакеты
Наименование
webreinvent/vaahcms
composer
Затронутые версииВерсия исправления
<= 2.3.1
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
4 месяца назад
Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php