← Back to CVE List

CVE-2023-37658

Published: 2023-07-11T15:15Z
Last Modified: 2024-11-21T08:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS > MITRE Terms of Use apply – see LICENSE‑MITRE.txt