CVE-2023-39115: Malicious File Upload
Published Aug 4, 2023
·Updated
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
Credit
Rajdip Dey Sarkar
Affected Software
1 affected component
Campcodes Complete Online Matrimonial Website System Script=3.3
Event History
Aug 4, 2023
Exploit Published
12:00 AM
Known Exploited
12:00 AM
Aug 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-39115?
The severity of CVE-2023-39115 is classified as high due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2023-39115?
To fix CVE-2023-39115, it is recommended to sanitize user input and implement proper validation for uploaded SVG documents.
3
What type of vulnerability is CVE-2023-39115?
CVE-2023-39115 is a Cross-Site Scripting (XSS) vulnerability.
4
Which versions of Campcodes Online Matrimonial Website System Script are affected by CVE-2023-39115?
CVE-2023-39115 affects version 3.3 of the Campcodes Online Matrimonial Website System Script.
5
Can CVE-2023-39115 be exploited by an attacker?
Yes, CVE-2023-39115 can be exploited by an attacker to execute arbitrary scripts in the context of a victim's browser.