** DISPUTED ** Concrete CMS v9.2.1... CVE-2023-44763

- AV AC AU C I A
发布: 2023-10-10
修订: 2024-04-11

** DISPUTED ** Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息