CVE-2023-28158

CVSS v3.1 5.4 (Medium)
54% Progress
EPSS 0.11 % (44th)
0.11% Progress
Affected Products 1
Advisories 1

Privilege escalation via stored XSS using the file upload service to upload malicious content.
The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2023-03-29 13:15:08
(17 months ago)
Updated Date
2023-04-18 03:15:07
(17 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Archiva from 2.0 version and prior 2.2.10 version cpe:2.3:a:apache:archiva >= 2.0 < 2.2.10
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...