CVE-2023-24369: XSS
Published Feb 17, 2023
·Updated
A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function.
Affected Software
1 affected component
UJCMS UJCMS>=4.1.3<5.5.1
Event History
Feb 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24369?
The severity of CVE-2023-24369 is classified as medium with a CVSS score of 6.1.
2
How does the XSS vulnerability in UJCMS v4.1.3 occur?
The XSS vulnerability in UJCMS v4.1.3 occurs by injecting a crafted payload into the URL parameter under the Add New Articles function, allowing attackers to execute arbitrary web scripts or HTML.
3
Can attackers execute arbitrary web scripts with CVE-2023-24369?
Yes, attackers can execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function in UJCMS v4.1.3.