ZeroHour

CVE-2017-15948

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p46
Published
()
Modified
Description

Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.

Vendors
grabaperch
Products
perch
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.