CVE-2023-3845: mooSocial mooDating URL ajax_invite cross site scripting
A vulnerability was found in mooSocial mooDating 1.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /friends/ajaxinvite of the component URL Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235196. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3845?
The severity of CVE-2023-3845 is medium.
What is the affected software of CVE-2023-3845?
The affected software of CVE-2023-3845 is mooSocial mooDating 1.2.
What is the vulnerability type of CVE-2023-3845?
The vulnerability type of CVE-2023-3845 is cross site scripting (XSS).
Is CVE-2023-3845 exploitable remotely?
Yes, CVE-2023-3845 can be exploited remotely.
Are there any known exploits for CVE-2023-3845?
Yes, known exploits for CVE-2023-3845 can be found at the following references: - [Exploit-DB](https://www.exploit-db.com/exploits/51628) - [Packet Storm Security](http://packetstormsecurity.com/files/173691/mooDating-1.2-Cross-Site-Scripting.html) - [VulDB](https://vuldb.com/?ctiid.235196)