ZeroHour

CVE-2023-26961

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p40
Published
()
Modified
Description

Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.

Vendors
alteryx
Products
alteryx server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.