First published: Thu Sep 28 2023(Updated: )
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpkobo AjaxNewsTicker | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41447 is a Cross Site Scripting (XSS) vulnerability in the phpkobo AjaxNewTicker v.1.0.5 component.
CVE-2023-41447 allows a remote attacker to execute arbitrary code by leveraging a crafted payload in the subcmd parameter of the index.php component.
The severity of CVE-2023-41447 is medium with a CVSS score of 6.1.
To fix CVE-2023-41447, update to a version of phpkobo AjaxNewTicker beyond v.1.0.5 that includes a patch for the vulnerability.
You can find more information about CVE-2023-41447 at the following references: http://ajaxnewsticker.com, http://phpkobo.com, and https://gist.github.com/RNPG/56b9fe4dcc3a248d4288bde5ffb3a5b3.