CVE-2023-32671: BuddyBoss XSS vulnerability
Published Oct 3, 2023
·Updated
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.
Affected Software
1 affected component
Buddyboss Buddyboss Wordpress=2.2.9
Event History
Oct 3, 2023
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this stored XSS vulnerability?
The vulnerability ID is CVE-2023-32671.
2
What software is affected by this stored XSS vulnerability?
BuddyBoss Platform version 2.2.9 is affected by this vulnerability.
3
How does this vulnerability impact the affected software?
This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium, with a CVSS score of 5.4.
5
How can I fix this stored XSS vulnerability?
To fix this vulnerability, update BuddyBoss Platform to a version that is not affected, or apply the available security patch from the software vendor.