First published: Wed Sep 27 2023(Updated: )
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpkobo AjaxNewsTicker | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41451 is medium with a CVSS score of 6.1.
CVE-2023-41451 affects phpkobo AjaxNewTicker version 1.0.5.
The Cross Site Scripting vulnerability in CVE-2023-41451 allows a remote attacker to execute arbitrary code.
The vulnerability in CVE-2023-41451 can be exploited by sending a crafted payload to the txt parameter in the index.php component.
It is recommended to update phpkobo AjaxNewTicker to a version that addresses the Cross Site Scripting vulnerability in CVE-2023-41451.