CVE-2023-3755: Creativeitem Atlas Business Directory Listing filter_listings cross site scripting
A vulnerability has been found in Creativeitem Atlas Business Directory Listing 2.13 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /home/filterlistings. The manipulation of the argument price-range leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-234427. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3755?
The severity of CVE-2023-3755 is medium with a CVSS score of 6.1.
What can an attacker do with CVE-2023-3755?
An attacker can exploit CVE-2023-3755 to perform cross-site scripting (XSS) attacks.
How does CVE-2023-3755 affect Creativeitem Atlas Business Directory Listing?
CVE-2023-3755 affects Creativeitem Atlas Business Directory Listing version 2.13, allowing for the manipulation of the 'price-range' argument to perform XSS attacks.
How can I fix CVE-2023-3755?
To fix CVE-2023-3755, it is recommended to update Creativeitem Atlas Business Directory Listing to a version that addresses the vulnerability.
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.