Privilege escalation via stored XSS using the file upload service to upload malicious content.
The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. | Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. |
Wed, 23 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: apache
Published: 2023-03-29T12:21:46.932Z
Updated: 2025-02-13T16:45:40.751Z
Reserved: 2023-03-13T02:37:38.879Z
Link: CVE-2023-28158

Updated: 2024-08-02T12:30:24.174Z

Status : Modified
Published: 2023-03-29T13:15:08.313
Modified: 2025-02-13T17:16:14.527
Link: CVE-2023-28158

No data.