Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6qjf-7g3j-qx25 | Neos CMS Cross Site Scripting vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T17:16:30.857Z
Reserved: 2023-07-10T00:00:00
Link: CVE-2023-37611
No data.
Status : Modified
Published: 2023-09-18T22:15:45.803
Modified: 2024-11-21T08:12:01.843
Link: CVE-2023-37611
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA