{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-26T01:35:00.528","vulnerabilities":[{"cve":{"id":"CVE-2023-6551","sourceIdentifier":"cvd@cert.pl","published":"2024-01-04T16:15:09.380","lastModified":"2026-06-17T06:50:58.287","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. \n\n\nDevelopers must be aware of that fact and use extension whitelisting accompanied by forcing the server to always provide content-type based on the file extension. \n\n\nThe README has been updated to include these guidelines."},{"lang":"es","value":"Como librería simple, class.upload.php no realiza una verificación en profundidad de los archivos cargados, lo que permite una vulnerabilidad de XSS almacenado cuando se usa la configuración predeterminada. Los desarrolladores deben ser conscientes de este hecho y utilizar la lista blanca de extensiones, además de obligar al servidor a proporcionar siempre el tipo de contenido según la extensión del archivo. El README se ha actualizado para incluir estas pautas."}],"affected":[{"source":"cvd@cert.pl","affectedData":[{"vendor":"class.upload.php","product":"class.upload.php","defaultStatus":"affected","repo":"https://github.com/verot/class.upload.php","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-08T20:16:15.657075Z","id":"CVE-2023-6551","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cvd@cert.pl","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:verot:class.upload.php:-:*:*:*:*:*:*:*","matchCriteriaId":"A49113E8-9207-45CE-981C-4AF0D4B1EC93"}]}]}],"references":[{"url":"https://cert.pl/en/posts/2024/01/CVE-2023-6551","source":"cvd@cert.pl","tags":["Third Party Advisory"]},{"url":"https://cert.pl/posts/2024/01/CVE-2023-6551","source":"cvd@cert.pl","tags":["Third Party Advisory"]},{"url":"https://cert.pl/en/posts/2024/01/CVE-2023-6551","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://cert.pl/posts/2024/01/CVE-2023-6551","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}