CVE-2023-32670: BuddyBoss XSS vulnerability
Published Oct 3, 2023
·Updated
Cross-Site Scripting vulnerability
in BuddyBoss 2.2.9 version
, which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.
Affected Software
1 affected component
Buddyboss Buddyboss Wordpress=2.2.9
Event History
Oct 3, 2023
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-32670.
2
What is the severity of CVE-2023-32670?
The severity of CVE-2023-32670 is critical (5.4).
3
What is the affected software version?
The affected software version is BuddyBoss 2.2.9.
4
How does the vulnerability in BuddyBoss version 2.2.9 work?
The vulnerability allows a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, which can assign a persistent javascript payload triggered by the associated image.
5
Is there a fix available for CVE-2023-32670?
Please refer to the vendor's website or official security advisory for a fix or patch.