CVE-2023-43325: XSS
A reflected cross-site scripting (XSS) vulnerability in the data[redirecturl] parameter of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43325?
CVE-2023-43325 is a reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8.
How does CVE-2023-43325 affect mooSocial?
CVE-2023-43325 affects mooSocial v3.1.8 by allowing attackers to steal user's session cookies and impersonate their account via a crafted URL.
What is the severity of CVE-2023-43325?
The severity of CVE-2023-43325 is medium with a CVSS score of 6.1.
How can I fix CVE-2023-43325 in my mooSocial installation?
To fix CVE-2023-43325, you should update your mooSocial installation to a version where the vulnerability is patched.
Where can I find more information about CVE-2023-43325?
You can find more information about CVE-2023-43325 on the GitHub repository link (https://github.com/ahrixia/CVE-2023-43325) and the official mooSocial website (https://moosocial.com/).