CVE-2023-37658: Fastposter Fast-Poster

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS

Affected products

Published 2023-07-11. Last modified 2026-06-17.