CVE-2023-44763
Summary
| CVE | CVE-2023-44763 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-10 12:15:00 UTC |
| Updated | 2023-11-07 04:21:00 UTC |
| Description | ** DISPUTED ** Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Allowed File Types |
MISC |
web.archive.org |
|
| GitHub - sromanhu/CVE-2023-44763_ConcreteCMS-Arbitrary-file-upload-Thumbnail: ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored. |
MISC |
github.com |
|
| Security Advisory 2023-10-25 Concrete CMS rejects CVE-2023-44763 |
MISC |
www.concretecms.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995541 PHP (Composer) Security Update for concrete5/concrete5 (GHSA-wrp2-6v6j-hfmg)