Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.
References
Configurations
History
21 Nov 2024, 08:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-01 22:15
Updated : 2024-11-21 08:28
NVD link : CVE-2023-46448
Mitre link : CVE-2023-46448
CVE.ORG link : CVE-2023-46448
JSON object : View
Products Affected
dmpop
- mejiro
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')