Vulnerability Description
This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pekeupload Project | Pekeupload | - |
Related Weaknesses (CWE)
References
- https://github.com/moxiecode/plupload/blob/120cc0b5dd3373d7181fd11b06ac2557c890dBroken LinkThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-PEKEUPLOAD-1584360ExploitThird Party Advisory
- https://github.com/moxiecode/plupload/blob/120cc0b5dd3373d7181fd11b06ac2557c890dBroken LinkThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-PEKEUPLOAD-1584360ExploitThird Party Advisory
FAQ
What is CVE-2021-23673?
CVE-2021-23673 is a vulnerability with a CVSS score of 5.4 (MEDIUM). This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.
How severe is CVE-2021-23673?
CVE-2021-23673 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23673?
Check the references section above for vendor advisories and patch information. Affected products include: Pekeupload Project Pekeupload.