Stored XSS through privileged upload of Media Manager file followed by renaming
CVE-2023-52083

2LOW

Key Information:

Vendor

wintercms

Status
Vendor
CVE Published:
28 December 2023

What is CVE-2023-52083?

Winter is a free, open-source content management system. Prior to 1.2.4, users with the media.manage_media permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack. This issue has been patched in v1.2.4.

Affected Version(s)

winter < 1.2.4

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.