First published: Thu Aug 03 2023(Updated: )
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Xoops | =2.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36217 is a Cross Site Scripting vulnerability in Xoops CMS v.2.5.10.
CVE-2023-36217 allows a remote attacker to execute arbitrary code via the category name field of the image manager function in Xoops CMS v.2.5.10.
CVE-2023-36217 is considered critical with a severity value of 9.
To fix CVE-2023-36217, you should update Xoops CMS to version 2.5.10 or later.
You can find more information about CVE-2023-36217 in the official Xoops CMS releases page (https://github.com/XOOPS/XoopsCore25/releases/tag/v2.5.10) and the Exploit Database (https://www.exploit-db.com/exploits/51520).