First published: Thu Sep 28 2023(Updated: )
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpkobo AjaxNewsTicker | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41450 is high with a score of 8.8.
A remote attacker can exploit CVE-2023-41450 by sending a crafted payload to the 'reque' parameter.
The affected software version of CVE-2023-41450 is phpkobo AjaxNewsTicker v.1.0.5.
There is no publicly disclosed fix available for CVE-2023-41450 at the moment.
You can find more information about CVE-2023-41450 at the following references: http://ajaxnewsticker.com, http://phpkobo.com, and https://gist.github.com/RNPG/e11af10e1bd3606de8b568033d932589.