cve/2023/CVE-2023-40461.md
2024-06-18 02:51:15 +02:00

915 B

CVE-2023-40461

Description

The ACEManagercomponent of ALEOS 4.16 and earlier allows anauthenticated userwith Administrator privileges to access a fileupload field whichdoes not fully validate the file name, creating aStored Cross-SiteScripting condition.

POC

Reference

Github

No PoCs found on GitHub currently.