CVE-2023-23735: WordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email HTML Injection Vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23735?
CVE-2023-23735 has been categorized as a high severity vulnerability due to improper neutralization of script-related HTML tags leading to code injection.
What is CVE-2023-23735?
CVE-2023-23735 is an improper neutralization of script-related HTML tags vulnerability in Brainstorm Force Spectra affecting versions up to 2.3.0.
How do I fix CVE-2023-23735?
To mitigate CVE-2023-23735, update Brainstorm Force Spectra to the latest version beyond 2.3.0 where the vulnerability has been addressed.
Which versions of Brainstorm Force Spectra are affected by CVE-2023-23735?
CVE-2023-23735 affects all versions of Brainstorm Force Spectra from n/a through 2.3.0.
What are the potential impacts of CVE-2023-23735?
Exploitation of CVE-2023-23735 can allow unauthorized code execution through XSS attacks, compromising the affected web application.