CVE-2023-43873: XSS
Published Sep 28, 2023
·Updated
A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.
Affected Software
1 affected component
e107 E107 Cms=2.3.2
Event History
Sep 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Cross Site Scripting (XSS) vulnerability?
The vulnerability ID for this Cross Site Scripting (XSS) vulnerability is CVE-2023-43873.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is e107 CMS v.2.3.2.
3
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability by executing arbitrary code via a crafted script in the Name field of the Manage Menu.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium, with a severity value of 5.4.
5
How can I fix this Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2?
To fix this vulnerability, update to a patched version of e017 CMS, if available, or follow the recommended security measures provided by the vendor.