Логотип exploitDog
bind:CVE-2023-52083
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-52083

Количество 2

Количество 2

nvd логотип

CVE-2023-52083

около 2 лет назад

Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack. This issue has been patched in v1.2.4.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-4wvw-75qh-fqjp

около 2 лет назад

Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming

CVSS3: 2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-52083

Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack. This issue has been patched in v1.2.4.

CVSS3: 2
0%
Низкий
около 2 лет назад
github логотип
GHSA-4wvw-75qh-fqjp

Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming

CVSS3: 2
0%
Низкий
около 2 лет назад

Уязвимостей на страницу