CVE-2023-53903: WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Upload
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53903?
CVE-2023-53903 has been classified as a medium severity vulnerability due to its potential for allowing persistent cross-site scripting attacks.
How do I fix CVE-2023-53903?
To fix CVE-2023-53903, it is essential to update WebsiteBaker to the latest version where this vulnerability has been addressed.
Who is affected by CVE-2023-53903?
CVE-2023-53903 affects users of WebsiteBaker version 2.13.3 that allow authenticated users to upload SVG files.
What types of attacks are possible with CVE-2023-53903?
Attackers can exploit CVE-2023-53903 to upload malicious SVG files that execute JavaScript when viewed, potentially compromising user sessions.
Is CVE-2023-53903 a remote or local vulnerability?
CVE-2023-53903 is a local vulnerability that requires authenticated user access to exploit.