SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-45280

Yamcs 5.8.6 allows XSS (issue 2 of 2).

MEDIUM 5.4EPSS 0.53%

Does this matter?

Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.

Description

Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.53% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
spaceapplications/yamcs
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.