CVE-2023-44763
10.10.2023, 12:15
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.Enginsight
Vendor | Product | Version |
---|---|---|
concretecms | concrete_cms | 9.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References