Логотип exploitDog
bind:CVE-2023-53884
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53884

Количество 2

Количество 2

nvd логотип

CVE-2023-53884

около 2 месяцев назад

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-557f-ppxv-gpgc

около 2 месяцев назад

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53884

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-557f-ppxv-gpgc

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу