CVE-2023-46467: XSS
Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46467?
CVE-2023-46467 is a cross-site scripting vulnerability in juzawebCMS v.3.4 and earlier versions that allows a remote attacker to execute arbitrary code by sending a malicious payload to the username parameter of the registration page.
How severe is CVE-2023-46467?
CVE-2023-46467 has a severity score of 5.4, which is considered medium.
Which software versions are affected by CVE-2023-46467?
juzawebCMS versions up to and including 3.4 are affected by CVE-2023-46467.
How can an attacker exploit CVE-2023-46467?
An attacker can exploit CVE-2023-46467 by crafting a payload and sending it to the username parameter of the registration page.
Is there a fix available for CVE-2023-46467?
It is recommended to upgrade to a version of juzawebCMS that is later than 3.4 to mitigate the CVE-2023-46467 vulnerability.