Record summary

CVE-2021-23562 has a selected CVSS score of 4.2 (medium).

Description

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 18, 2013 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

3
ProductSourceVersion rangeStatus

plupload

CVE ListBefore 2.3.9affected
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 2.3.9 · Fixed in 2.3.9affected

References

8