Vulnerabilities > CVE-2023-6142 - Unspecified vulnerability in Armanidrisi DEV Blog 1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |