Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-52083

Опубликовано: 28 дек. 2023
Источник: nvd
CVSS3: 2
CVSS3: 4.8
EPSS Низкий

Описание

Winter is a free, open-source content management system. Prior to 1.2.4, users with the media.manage_media permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack. This issue has been patched in v1.2.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:*
Версия до 1.2.4 (исключая)

EPSS

Процентиль: 58%
0.0036
Низкий

2 Low

CVSS3

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 2
github
около 2 лет назад

Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming

EPSS

Процентиль: 58%
0.0036
Низкий

2 Low

CVSS3

4.8 Medium

CVSS3

Дефекты

CWE-79