CVE-2023-2398: Icegram Engage < 3.1.12 - Reflected XSS
Published Jun 12, 2023
·Updated
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
Icegram Icegram Engage WordPress<3.1.12
Event History
Jun 12, 2023
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID associated with this vulnerability?
The vulnerability ID associated with this vulnerability is CVE-2023-2398.
2
What is the severity of CVE-2023-2398?
The severity of CVE-2023-2398 is medium.
3
What is the affected software?
The affected software is Icegram Engage WordPress plugin version up to and excluding 3.1.12.
4
What is the impact of CVE-2023-2398?
The vulnerability in Icegram Engage WordPress plugin allows for a reflected cross-site scripting (XSS) attack, which could be used against high privilege users such as admins.
5
Where can I find more information about CVE-2023-2398?
More information about CVE-2023-2398 can be found at https://wpscan.com/vulnerability/16d47d20-58aa-4d04-9275-fd91ce926ff3.