CVE-2023-43326: XSS
Published Sep 25, 2023
·Updated
A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.
Affected Software
1 affected component
mooSocial MooSocial=3.1.8
Event History
Sep 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-43326?
CVE-2023-43326 is a cross-site scripting (XSS) vulnerability in mooSocial v3.1.8.
2
How severe is CVE-2023-43326?
CVE-2023-43326 has a severity level of medium, with a CVSS score of 6.1.
3
How does CVE-2023-43326 affect mooSocial v3.1.8?
CVE-2023-43326 affects mooSocial v3.1.8 through the change email function, allowing for potential cross-site scripting attacks.
4
How can I fix CVE-2023-43326 in mooSocial v3.1.8?
To fix CVE-2023-43326, it is recommended to update mooSocial to a version that has addressed this vulnerability.
5
Where can I find more information about CVE-2023-43326?
You can find more information about CVE-2023-43326 on the GitHub repository and the official moosocial.com website.