CVE-2017-15948

Publication date

2017-10-28 00:00:00

Family

mitre

State

PUBLISHED

Description

Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.