Medium severity5.4NVD Advisory· Published Jan 4, 2024· Updated Jun 17, 2026
CVE-2023-6551
CVE-2023-6551
Description
As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used.
Developers must be aware of that fact and use extension whitelisting accompanied by forcing the server to always provide content-type based on the file extension.
The README has been updated to include these guidelines.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
verot/class.upload.phpPackagist | <= 2.1.6 | — |
Affected products
3- Range: 0
- cpe:2.3:a:verot:class.upload.php:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- cert.pl/en/posts/2024/01/CVE-2023-6551nvdThird Party AdvisoryWEB
- cert.pl/posts/2024/01/CVE-2023-6551nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-v6f4-jwv9-682wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-6551ghsaADVISORY
- github.com/verot/class.upload.php/commit/befbccc2330b0ccb148fc87495896bd7b57f8c57ghsaWEB
News mentions
0No linked articles in our index yet.