CVE-2023-45542: XSS
Published Oct 16, 2023
·Updated
Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.
Affected Software
1 affected component
mooSocial MooSocial=3.1.8
Event History
Oct 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this cross site scripting vulnerability in mooSocial 3.1.8?
The vulnerability ID is CVE-2023-45542.
2
What is the severity of CVE-2023-45542?
The severity of CVE-2023-45542 is medium.
3
How can a remote attacker exploit CVE-2023-45542?
A remote attacker can exploit CVE-2023-45542 by crafting a script and using it in the q parameter of the Search function.
4
What can a remote attacker obtain through the exploit of CVE-2023-45542?
Through the exploit of CVE-2023-45542, a remote attacker can obtain sensitive information.
5
Is there a fix available for the cross site scripting vulnerability in mooSocial 3.1.8?
Yes, a fix is available for the cross site scripting vulnerability in mooSocial 3.1.8. Please refer to the vendor for the patch or update.