Vulnerability Description
Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grabaperch | Perch | 3.0.3 |
Related Weaknesses (CWE)
References
- https://www.vulnerability-lab.com/get_content.php?id=2067ExploitIssue TrackingPatch
- https://www.vulnerability-lab.com/get_content.php?id=2067ExploitIssue TrackingPatch
FAQ
What is CVE-2017-15948?
CVE-2017-15948 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin...
How severe is CVE-2017-15948?
CVE-2017-15948 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15948?
Check the references section above for vendor advisories and patch information. Affected products include: Grabaperch Perch.