CVE-2023-3464: SimplePHPscripts Classified Ads Script URL Parameter preview.php cross site scripting
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack remotely. It is recommended to upgrade the affected component. VDB-232710 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SimplePHPscripts Classified Ads Script 1.8to a version that resolves this vulnerability.Fixed in 1.8Patch VDB-232710
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3464?
CVE-2023-3464 has been classified as a problematic vulnerability due to the risk of cross-site scripting.
How do I fix CVE-2023-3464?
To fix CVE-2023-3464, it's recommended to sanitize and validate input parameters in the URL Parameter Handler function.
What components are affected by CVE-2023-3464?
CVE-2023-3464 affects the URL Parameter Handler component specifically within SimplePHPscripts Classified Ads Script version 1.8.
What type of attack does CVE-2023-3464 enable?
CVE-2023-3464 enables a cross-site scripting (XSS) attack through manipulation of the argument 'p' in the /preview.php file.
Which version of the software is affected by CVE-2023-3464?
Only version 1.8 of the SimplePHPscripts Classified Ads Script is affected by CVE-2023-3464.