Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-43875
HistoryOct 19, 2023 - 12:00 a.m.

CVE-2023-43875

2023-10-1900:00:00
mitre
github.com
3
cross-site scripting
subrion cms
arbitrary web scripts
crafted payload
injection
database host
database name
database user
admin username
admin email

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

21.3%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

21.3%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-43875