PT-2023-23272 · Unknown · Serenity Serene+1

Fabian Densborn

·

Published

2023-04-27

·

Updated

2025-01-31

·

CVE-2023-31285

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Serenity Serene versions prior to 6.7.0 StartSharp versions prior to 6.7.0
Description A security issue was discovered where users can upload temporary files with certain file endings, such as .html or .htm, that contain a malicious payload. This payload can be used to send a link to an administrator user, potentially leading to exploitation.
Recommendations For Serenity Serene versions prior to 6.7.0, update to version 6.7.0 or later to resolve the issue. For StartSharp versions prior to 6.7.0, update to version 6.7.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of .html and .htm files to prevent potential exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-31285
GHSA-93H6-WX7R-MGFP

Affected Products

Serenity Serene
Startsharp