WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
History

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Websitebaker
Websitebaker websitebaker
Vendors & Products Websitebaker
Websitebaker websitebaker

Tue, 16 Dec 2025 17:30:00 +0000


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
Title WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Upload
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-16T17:03:48.887Z

Updated: 2025-12-16T21:44:03.498Z

Reserved: 2025-12-16T00:10:40.314Z

Link: CVE-2023-53903

cve-icon Vulnrichment

Updated: 2025-12-16T21:44:00.323Z

cve-icon NVD

Status : Received

Published: 2025-12-16T17:16:02.700

Modified: 2025-12-16T18:16:07.460

Link: CVE-2023-53903

cve-icon Redhat

No data.