GHSA-fpph-mqc8-h6q5
Dashboard / Vulnerabilities / GHSA-fpph-mqc8-h6q5
Summary: Withdrawn Advisory: Unrestricted File Upload affecting automad
Details: ## Withdrawn Advisory This advisory has been withdrawn because JavaScript execution is the intended functionality of automad. This link is maintained to preserve external references. ## Original Description A vulnerability was found in automad up to 1.10.9. This affects the function upload of the file `FileCollectionController.php` of the component `Content Type Handler`. The manipulation leads to unrestricted upload. The attack may be launched remotely and an exploit has been disclosed publicly.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-7036, https://github.com/marcantondahmen/automad, https://github.com/screetsec/VDD/tree/main/Automad%20CMS/Unrestricted%20File%20Upload, https://vuldb.com/?ctiid.248685, https://vuldb.com/?id.248685
Affected packages
Package
Name: automad/automad
Purl: pkg:composer/automad/automad
Affected ranges
Type: ECOSYSTEM
Events:
