CVE-2023-37733: XSS
Published Jul 19, 2023
·Updated
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
Affected Software
1 affected component
TDuckCloud tduck-platform=4.0
Event History
Jul 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this arbitrary file upload vulnerability?
The vulnerability ID for this arbitrary file upload vulnerability is CVE-2023-37733.
2
What is the severity level of CVE-2023-37733?
The severity level of CVE-2023-37733 is medium (6.1).
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by uploading a crafted HTML file, which allows them to execute arbitrary code.
4
What software versions are affected by CVE-2023-37733?
CVE-2023-37733 affects tduck-platform version 4.0.
5
Is there a fix available for CVE-2023-37733?
Yes, please update your tduck-platform to a version that is not vulnerable to this arbitrary file upload vulnerability.