vendor:
Kirby Panel
by:
Ishaq Mohammed
5,4
CVSS
MEDIUM
Stored Cross Site Scripting
79
CWE
Product Name: Kirby Panel
Affected Version From: 2.3.3
Affected Version To: 2.5.7
Patch Exists: YES
Related CWE: CVE-2017-16807
CPE: 2.3.3/2.4.2/2.5.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2017
KirbyCMS <2.5.7 Stored Cross Site Scripting
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.
Mitigation:
The vulnerability is patched by the vendor in the version 2.5.7.