First published: Thu Sep 28 2023(Updated: )
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpkobo AjaxNewsTicker | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41446 is medium.
CVE-2023-41446 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component of phpkobo AjaxNewTicker v.1.0.5.
To fix the Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5, you should update to a version of the software that is not affected by the vulnerability.
Yes, you can find references about CVE-2023-41446 on the following websites: http://ajaxnewsticker.com, http://phpkobo.com, and https://gist.github.com/RNPG/4bb91170f8ee50b395427f26bc96a1f2.
The CWE ID for CVE-2023-41446 is 79.