Vulnerability Description
Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Neos | Neos Cms | 8.3.3 |
Related Weaknesses (CWE)
References
- https://github.com/neos/neos-development-collection/pull/4812
- https://rodelllemit.medium.com/stored-xss-in-neo-cms-8-3-3-9bd1cb973c5bExploit
- https://github.com/neos/neos-development-collection/pull/4812
- https://rodelllemit.medium.com/stored-xss-in-neo-cms-8-3-3-9bd1cb973c5bExploit
FAQ
What is CVE-2023-37611?
CVE-2023-37611 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
How severe is CVE-2023-37611?
CVE-2023-37611 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-37611?
Check the references section above for vendor advisories and patch information. Affected products include: Neos Neos Cms.