CVE-2023-37272
Specifically crafted file names allow an XSS attack to inject code that is executed with the browser.
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler (JS1). The vulnerability does not affect branch 2.x of JobScheduler (JS7) for releases after 2.1.0. The vulnerability is resolved with release 1.13.19.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sos-berlin/jobscheduler
- Source
- security-advisories@github.com
References
- https://change.sos-berlin.com/browse/SET-226Patch, Vendor Advisory
- https://github.com/sos-berlin/joc-cockpit/security/advisories/GHSA-qr44-gm3x-7hfcThird Party Advisory
- https://change.sos-berlin.com/browse/SET-226Patch, Vendor Advisory
- https://github.com/sos-berlin/joc-cockpit/security/advisories/GHSA-qr44-gm3x-7hfcThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.