CVE-2023-37785: XSS
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smilecode parameter of the component /editprofile.php.
Other sources
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smilecode parameter of the component /editprofile.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37785?
CVE-2023-37785 is a cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before that allows attackers to execute arbitrary web scripts or HTML.
How can an attacker exploit CVE-2023-37785?
An attacker can exploit CVE-2023-37785 by injecting a crafted payload into the 'smile_code' parameter of the component '/editprofile.php'. This payload can contain malicious web scripts or HTML.
What is the severity of CVE-2023-37785?
CVE-2023-37785 has a medium severity level.
Which software versions are affected by CVE-2023-37785?
ImpressCMS versions up to and including v1.4.5 are affected by CVE-2023-37785.
How can I fix CVE-2023-37785?
To fix CVE-2023-37785, it is recommended to update ImpressCMS to a version that is not vulnerable, if available. Alternatively, apply any patches or security updates provided by the vendor.