CVE-2023-4173: mooSocial mooStore index cross site scripting
Published Aug 6, 2023
·Updated
A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. Affected is an unknown function of the file /search/index. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236208.
Credit
CraCkEr
Affected Software
1 affected component
mooSocial mooStore=3.1.6
Event History
Aug 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
12:15 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Aug 8, 2023
Exploit Published
12:00 AM
Known Exploited
12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-4173.
2
What is the severity of CVE-2023-4173?
The severity of CVE-2023-4173 is medium with a CVSS score of 6.1.
3
What is the affected software version?
The affected software version is mooSocial mooStore 3.1.6.
4
How does this vulnerability occur?
This vulnerability occurs due to cross-site scripting (XSS) in the /search/index function of mooSocial mooStore 3.1.6.
5
Is it possible to launch the attack remotely?
Yes, it is possible to launch the attack remotely.