{"id":"CVE-2023-37611","aliases":["BIT-neos-2023-37611","GHSA-6qjf-7g3j-qx25"],"url":"https://o3.security/vulnerability/CVE-2023-37611","summary":"Neos CMS Cross Site Scripting vulnerability","details":"Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.","published":"2023-09-18T00:00:00Z","modified":"2026-07-15T01:48:57.946031464Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"neos/media-browser","fixedVersion":"7.3.19"},{"ecosystem":"Packagist","name":"neos/media-browser","fixedVersion":"8.0.16"},{"ecosystem":"Packagist","name":"neos/media-browser","fixedVersion":"8.1.11"},{"ecosystem":"Packagist","name":"neos/media-browser","fixedVersion":"8.2.11"},{"ecosystem":"Packagist","name":"neos/media-browser","fixedVersion":"8.3.9"}],"fix":{"url":"https://github.com/neos/neos-development-collection/pull/4812","label":"neos/neos-development-collection#4812"},"references":[{"type":"WEB","url":"https://rodelllemit.medium.com/stored-xss-in-neo-cms-8-3-3-9bd1cb973c5b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37611.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37611"},{"type":"FIX","url":"https://github.com/neos/neos-development-collection/pull/4812"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:57.946031464Z"}}