← Back to CVE List

CVE-2023-44763

Published: 2023-10-10T12:15Z
Last Modified: 2024-11-21T08:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt