CVE-2023-26961
Summary
| CVE | CVE-2023-26961 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-08 20:15:00 UTC |
| Updated | 2023-08-21 17:15:00 UTC |
| Description | Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alteryx | Alteryx Server | 2022.1.1.42590 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2023-26961 - PoC · GitHub | MISC | gist.github.com | |
| Data Science and Analytics Automation Platform | Alteryx | MISC | alteryx.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.