CVE-2023-7259: zzdevelop lenosp Adduser Page cross site scripting

Published May 24, 2024
·
Updated

DISPUTED A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-266127. NOTE: The vendor rejected the issue because he claims that XSS which require administrative privileges are not of any use for attackers.

Affected Software

1 affected component
zzdevelop lenosp<=20230831

Event History

May 24, 2024
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Disputed
via NVD·07:15 AM
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Sep 3, 2026
Disputed
via NVD·02:15 AM

Frequently Asked Questions

1

What is the severity of CVE-2023-7259?

CVE-2023-7259 is classified as problematic, indicating a significant security risk.

2

What type of vulnerability is CVE-2023-7259?

CVE-2023-7259 is a cross-site scripting (XSS) vulnerability affecting the Adduser Page component.

3

How can I fix CVE-2023-7259?

To fix CVE-2023-7259, ensure proper input validation and sanitization on the username input to prevent script execution.

4

Which versions are affected by CVE-2023-7259?

CVE-2023-7259 affects zzdevelop lenosp versions up to and including 20230831.

5

What component is impacted by CVE-2023-7259?

CVE-2023-7259 specifically impacts the Adduser Page component of the zzdevelop lenosp software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203