PT-2023-26042 · Neos Cms · Neos Cms

Dlubitz

·

Publicado

2023-09-18

·

Atualizado

2024-03-06

·

CVE-2023-37611

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Neos CMS version 8.3.3
Description The issue allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file uploaded to the neos/management/media component. To exploit this, the attacker must be able to upload a maliciously crafted file or coerce someone with the needed access to upload the file. The attacker can use this vulnerability to deliver malicious code. It is possible to use Content Security Policy (CSP) to protect against attacks being executed from such a file.
Recommendations For Neos CMS version 8.3.3, consider disabling the upload of SVG files to the neos/management/media component until a patch is available. Implementing Content Security Policy (CSP) can also help protect against attacks being executed from maliciously crafted files.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-NEOS-2023-37611
CVE-2023-37611
GHSA-6QJF-7G3J-QX25

Produtos afetados

Neos Cms