PoC Index

CVE-2023-51252

MEDIUM 5.4EPSS 0.3%

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.30% chance of exploitation in the next 30 days, 22th percentile
Published
2024-01-10
Updated
2025-06-20

Proof-of-concept exploits (1)

References

Related