Lucene search

K
osvGoogleOSV:CVE-2023-37658
HistoryJul 11, 2023 - 3:15 p.m.

CVE-2023-37658

2023-07-1115:15:20
Google
osv.dev
3
cve-2023-37658
cross site scripting
file upload
binary check
file suffix check
apiuploadhandler.post

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

30.0%

fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

30.0%

Related for OSV:CVE-2023-37658