PoC Index

CVE-2023-4168

HIGH 7.5EPSS 46.0%

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Es wurde eine problematische Schwachstelle in Templatecookie Adlisting 2.14.0 ausgemacht. Betroffen hiervon ist ein unbekannter Ablauf der Datei /ad-list der Komponente Redirect Handler. Durch die Manipulation mit unbekannten Daten kann eine information disclosure-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
45.97% chance of exploitation in the next 30 days, 99th percentile
Nuclei
high
Published
2023-08-05
Updated
2024-08-02

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

References

Related