CVE-2023-36217: XSS
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-36217?
CVE-2023-36217 is a Cross Site Scripting vulnerability in Xoops CMS v.2.5.10.
How does CVE-2023-36217 impact Xoops CMS?
CVE-2023-36217 allows a remote attacker to execute arbitrary code via the category name field of the image manager function in Xoops CMS v.2.5.10.
How severe is CVE-2023-36217?
CVE-2023-36217 is considered critical with a severity value of 9.
How can I fix CVE-2023-36217?
To fix CVE-2023-36217, you should update Xoops CMS to version 2.5.10 or later.
Where can I find more information about CVE-2023-36217?
You can find more information about CVE-2023-36217 in the official Xoops CMS releases page (https://github.com/XOOPS/XoopsCore25/releases/tag/v2.5.10) and the Exploit Database (https://www.exploit-db.com/exploits/51520).