Lucene search

K
cveMitreCVE-2023-45881
HistoryNov 14, 2023 - 6:15 a.m.

CVE-2023-45881

2023-11-1406:15:29
CWE-79
mitre
web.nvd.nist.gov
8
cve-2023-45881
gibbonedu gibbon
xss
file upload
html code
nvd

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.0%

GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response.

Affected configurations

Nvd
Node
gibbonedugibbonRange25.0.00
VendorProductVersionCPE
gibbonedugibbon*cpe:2.3:a:gibbonedu:gibbon:*:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.0%

Related for CVE-2023-45881