CVE-2023-44812: XSS
Published Oct 9, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the adminredirecturl parameter of the user login function.
Affected Software
1 affected component
mooSocial MooSocial=3.1.8
Event History
Oct 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-44812.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code'.
3
What is the affected version of mooSocial?
The affected version of mooSocial is 3.1.8.
4
What is the severity of CVE-2023-44812?
The severity of CVE-2023-44812 is medium with a CVSS score of 6.1.
5
How can the attacker exploit this vulnerability?
The attacker can exploit this vulnerability by sending a crafted payload to the admin_redirect_url parameter of the user login function.