Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-38488

Опубликовано: 27 июл. 2023
Источник: nvd
CVSS3: 7.1
CVSS3: 8.8
EPSS Низкий

Описание

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update a Kirby content file (e.g. via a contact or comment form). Kirby sites are not affected if they don't allow write access for untrusted users or visitors.

A field injection in a content storage implementation is a type of vulnerability that allows attackers with content write access to overwrite content fields that the site developer didn't intend to be modified. In a Kirby site this can be used to alter site content, break site behavior or inject malicious data or code. The exact security risk depends on the field type and usage.

Kirby stores content of the site, of pages, files and users in text files by default. The text files use Kirby's KirbyData format where each field is separated by newlines and a line with four da

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.8.3 (исключая)
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 3.6.0 (включая) до 3.6.6.3 (исключая)
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 3.7.0 (включая) до 3.7.5.2 (исключая)
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 3.8.0 (включая) до 3.8.4.1 (исключая)
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 3.9.0 (включая) до 3.9.6 (исключая)

EPSS

Процентиль: 21%
0.0007
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-140
CWE-863

Связанные уязвимости

CVSS3: 7.1
github
больше 2 лет назад

Field injection in the KirbyData text storage handler

EPSS

Процентиль: 21%
0.0007
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-140
CWE-863