First published: Thu May 25 2023(Updated: )
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icecms | =1.0.0 | |
iCMS | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33356 is a Cross-Site Scripting (XSS) vulnerability in IceCMS v1.0.0.
CVE-2023-33356 has a severity rating of 5.4, which is considered medium.
CVE-2023-33356 allows attackers to inject malicious scripts into IceCMS, potentially leading to the theft of user information or session hijacking.
At the moment, there is no official patch or update available to fix CVE-2023-33356, but it is recommended to apply any available security updates and follow best security practices to mitigate the risk.
You can find more information about CVE-2023-33356 in the GitHub issue tracker: https://github.com/Thecosy/IceCMS/issues/8