CVE-2023-6142

CVSS V2 None CVSS V3 None
Description
Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.
Overview
  • CVE ID
  • CVE-2023-6142
  • Assigner
  • Fluid Attacks
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-11-20T23:24:48.652Z
  • Last Modified Date
  • 2023-11-20T23:24:48.652Z
History
Created Old Value New Value Data Type Notes
2024-06-25 06:42:21 Added to TrackCVE