{"id":"CVE-2023-37611","details":"Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.","aliases":["BIT-neos-2023-37611","GHSA-6qjf-7g3j-qx25"],"modified":"2026-04-11T12:45:54.821491Z","published":"2023-09-18T22:15:45.803Z","database_specific":{},"references":[{"type":"FIX","url":"https://github.com/neos/neos-development-collection/pull/4812"},{"type":"EVIDENCE","url":"https://rodelllemit.medium.com/stored-xss-in-neo-cms-8-3-3-9bd1cb973c5b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/neos/neos","events":[{"introduced":"0"},{"last_affected":"be01ac4f654be8666226d3b7ba207ebe1cc460aa"}],"database_specific":{"cpe":"cpe:2.3:a:neos:neos_cms:8.3.3:-:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"8.3.3-NA"}],"source":"CPE_FIELD"}}],"versions":["1.0.0-alpha1","1.0.0-alpha2","1.0.0-alpha3","1.0.0-alpha4","1.0.0-alpha5","1.0.0-alpha6","1.0.0-alpha7","1.0.0-beta1","1.0.0-beta2","7.3.9","8.2.0","8.2.1","8.2.2","8.3.0","8.3.1","8.3.2","8.3.3","historic-1.0.0-alpha1","historic-1.0.0-alpha2","historic-1.0.0-alpha4","historic-1.0.0-alpha5","historic-1.0.0-alpha6","historic-1.0.0-alpha7"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-37611.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}