Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
GHSA-6qjf-7g3j-qx25 | Neos CMS Cross Site Scripting vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T17:16:30.857Z
Reserved: 2023-07-10T00:00:00
Link: CVE-2023-37611

No data.

Status : Modified
Published: 2023-09-18T22:15:45.803
Modified: 2024-11-21T08:12:01.843
Link: CVE-2023-37611

No data.

No data.