First published: Wed Sep 27 2023(Updated: )
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpkobo AjaxNewsTicker | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41448 is medium with a CVSS score of 6.1.
The Cross-Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 manifests via a crafted payload to the ID parameter in the index.php component.
Version 1.0.5 of phpkobo AjaxNewTicker is affected by CVE-2023-41448.
CVE-2023-41448 is classified under the CWE-79 (Cross-Site Scripting) category.
To fix the Cross-Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5, it is recommended to update to a version that addresses the vulnerability or apply patches provided by the vendor.