Описание
Winter is a free, open-source content management system. Prior to 1.2.4, users with the media.manage_media permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack. This issue has been patched in v1.2.4.
Ссылки
- Patch
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.4 (исключая)
cpe:2.3:a:wintercms:winter:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.0036
Низкий
2 Low
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 2
github
около 2 лет назад
Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming
EPSS
Процентиль: 58%
0.0036
Низкий
2 Low
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-79