ZeroHour

CVE-2023-28158

CVSS 3.1
5.4 medium
EPSS
1%p65
Published
()
Modified
Description

Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.

Vendors
apache
Products
archiva
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.