CVE-2023-37658
11.07.2023, 15:15
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS
Vendor | Product | Version |
---|---|---|
fastposter | fast-poster | 2.15.0 |
𝑥
= Vulnerable software versions