Stored XSS Vulnerability in BlogEngine.NET 3.3.8.0 Allows Arbitrary JavaScript Injection via Specially Crafted File Upload

Stored XSS Vulnerability in BlogEngine.NET 3.3.8.0 Allows Arbitrary JavaScript Injection via Specially Crafted File Upload

CVE-2023-22856 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.

Learn more about our Web Application Penetration Testing UK.