CVE-2023-2862: SiteServer CMS search cross site scripting
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-229818 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2862.
What is the severity of CVE-2023-2862?
The severity of CVE-2023-2862 is medium with a severity value of 6.1.
What is the affected software of CVE-2023-2862?
The affected software of CVE-2023-2862 is SiteServer CMS up to version 7.2.1.
What is the CWE associated with CVE-2023-2862?
The CWE associated with CVE-2023-2862 is CWE-79 (Cross-Site Scripting).
How do I fix the vulnerability CVE-2023-2862?
To fix the vulnerability CVE-2023-2862, you should update SiteServer CMS to a version beyond 7.2.1.