Логотип exploitDog
bind:CVE-2023-53928
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53928

Количество 2

Количество 2

nvd логотип

CVE-2023-53928

около 2 месяцев назад

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-48f6-vw4q-5vcq

около 2 месяцев назад

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53928

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-48f6-vw4q-5vcq

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу