Количество 2
Количество 2
CVE-2023-44763
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.
GHSA-wrp2-6v6j-hfmg
ConcreteCMS vulnerable to Stored Cross-site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-44763 Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-wrp2-6v6j-hfmg ConcreteCMS vulnerable to Stored Cross-site Scripting | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу