SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-31285

An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0.

MEDIUM 6.1EPSS 0.78%

Does this matter?

Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.

Description

An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.78% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
serenity/serene · serenity/startsharp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.