CVE-2023-3542: ThinuTech ThinuCMS contact.php cross site scripting
A vulnerability was found in ThinuTech ThinuCMS 1.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument name/body leads to cross site scripting. The attack may be launched remotely. VDB-233294 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3542?
CVE-2023-3542 is classified as a problematic vulnerability affecting ThinuTech ThinuCMS 1.5.
How do I fix CVE-2023-3542?
To mitigate CVE-2023-3542, sanitization of the input for the arguments name and body in the /contact.php file is necessary to prevent cross site scripting.
What is the impact of CVE-2023-3542?
The impact of CVE-2023-3542 includes the potential for attackers to execute cross site scripting attacks remotely.
What versions of ThinuTech ThinuCMS are affected by CVE-2023-3542?
CVE-2023-3542 specifically affects ThinuTech ThinuCMS version 1.5.
Can CVE-2023-3542 be exploited remotely?
Yes, CVE-2023-3542 can be exploited remotely by manipulating input arguments.