CVE-2023-37658

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/07/2023
Last modified:
18/07/2023

Description

fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fastposter:fast-poster:2.15.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools