MEDIUM
Yamcs 5.8.6 allows XSS (issue 2 of 2)
Published Oct 19, 2023
5.4
MEDIUMCVSS 3.1
EPSS 0.53%
Description
Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.
Affected products
No data.
- 5.8.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2664 Advisory
- https://github.com/advisories/GHSA-643f-hpcc-2gv8 Advisory
- https://github.com/yamcs/yamcs/compare/yamcs-5.8.6...yamcs-5.8.7 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2023-45280
- https://www.linkedin.com/pulse/yamcs-vulnerability-assessment-visionspace-technologies ExploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 19, 2023
Updated Aug 2, 2024
Reserved Oct 6, 2023
Link CVE-2023-45280
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2023-2664 GHSA-643F-HPCC-2GV8 Assigner mitre
Published Oct 19, 2023
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2023-2664