Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-43376
HistorySep 20, 2023 - 12:00 a.m.

CVE-2023-43376

2023-09-2000:00:00
mitre
github.com
cross-site scripting
attackers
arbitrary web scripts
crafted payload

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

23.9%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

23.9%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-43376