CVE-2023-53906: ProjectSend r1605 Stored Cross-Site Scripting via Custom Assets Page
projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53906?
CVE-2023-53906 is considered a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2023-53906?
To fix CVE-2023-53906, ensure that you update ProjectSend to the latest version where this vulnerability has been addressed.
Who is affected by CVE-2023-53906?
CVE-2023-53906 affects authenticated administrators of ProjectSend who can modify the custom assets configuration.
What type of attack does CVE-2023-53906 enable?
CVE-2023-53906 enables stored cross-site scripting attacks, allowing attackers to inject malicious JavaScript.
Is CVE-2023-53906 easy to exploit?
Yes, CVE-2023-53906 can be easily exploited by crafted JavaScript payloads through the custom assets section of ProjectSend.