PoC Index

CVE-2023-3843

MEDIUM 6.1EPSS 6.0%

A vulnerability was found in mooSocial mooDating 1.2. It has been classified as problematic. Affected is an unknown function of the file /matchmakings/question of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-235194 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly. Es wurde eine problematische Schwachstelle in mooSocial mooDating 1.2 ausgemacht. Betroffen hiervon ist ein unbekannter Ablauf der Datei /matchmakings/question der Komponente URL Handler. Durch die Manipulation mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS
5.96% chance of exploitation in the next 30 days, 93th percentile
Nuclei
medium · CWE-79
Published
2023-07-23
Updated
2024-08-02

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

References

Related