First published: Thu Oct 19 2023(Updated: )
Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.yamcs:yamcs | <5.8.7 | 5.8.7 |
Spaceapplications Yacms | =5.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-45280.
The severity level of CVE-2023-45280 is not provided in the information provided.
CVE-2023-45280 allows XSS in Yamcs 5.8.6, which allows the execution of arbitrary JavaScript.
To fix CVE-2023-45280, upgrade Yamcs to version 5.8.7.
You can find more information about CVE-2023-45280 on the GitHub repository, LinkedIn post, and NVD website provided in the references.