CVE-2023-51252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/01/2024
Last modified:
20/06/2025

Description

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:publiccms:publiccms:4.0:*:*:*:*:*:*:*