CVE-2023-52083
Dashboard / Vulnerabilities / CVE-2023-52083
Summary: Stored XSS through privileged upload of Media Manager file followed by renaming
Details: Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack. This issue has been patched in v1.2.4.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52083.json, https://github.com/wintercms/winter/security/advisories/GHSA-4wvw-75qh-fqjp, https://nvd.nist.gov/vuln/detail/CVE-2023-52083, https://github.com/wintercms/winter/commit/2969daeea8dee64d292dbaa3778ea251e2a7e491
Affected packages
Package
Name:
Purl:
