From b4b5b843949586baa280ce14ba8347a67e652b17 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 Aug 2024 17:32:51 +0000 Subject: [PATCH] Publish GHSA-fpph-mqc8-h6q5 --- .../2023/12/GHSA-fpph-mqc8-h6q5/GHSA-fpph-mqc8-h6q5.json | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-fpph-mqc8-h6q5/GHSA-fpph-mqc8-h6q5.json b/advisories/github-reviewed/2023/12/GHSA-fpph-mqc8-h6q5/GHSA-fpph-mqc8-h6q5.json index 3b93440b408..93cbe8c23c7 100644 --- a/advisories/github-reviewed/2023/12/GHSA-fpph-mqc8-h6q5/GHSA-fpph-mqc8-h6q5.json +++ b/advisories/github-reviewed/2023/12/GHSA-fpph-mqc8-h6q5/GHSA-fpph-mqc8-h6q5.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-fpph-mqc8-h6q5", - "modified": "2023-12-29T18:35:29Z", + "modified": "2024-08-20T17:31:24Z", "published": "2023-12-21T18:30:23Z", + "withdrawn": "2024-08-20T17:31:24Z", "aliases": [ "CVE-2023-7036" ], - "summary": "Unrestricted File Upload affecting automad", - "details": "A vulnerability was found in automad up to 1.10.9. This affects the function upload of the file `FileCollectionController.php` of the component `Content Type Handler`. The manipulation leads to unrestricted upload. The attack may be launched remotely and an exploit has been disclosed publicly.", + "summary": "Withdrawn Advisory: Unrestricted File Upload affecting automad", + "details": "## Withdrawn Advisory\nThis advisory has been withdrawn because JavaScript execution is the intended functionality of automad. This link is maintained to preserve external references.\n\n## Original Description\nA vulnerability was found in automad up to 1.10.9. This affects the function upload of the file `FileCollectionController.php` of the component `Content Type Handler`. The manipulation leads to unrestricted upload. The attack may be launched remotely and an exploit has been disclosed publicly.", "severity": [ { "type": "CVSS_V3",