A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230467.
References
Link | Resource |
---|---|
https://gitee.com/gouguopen/office/issues/I74ZPU | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.230467 | Third Party Advisory |
https://vuldb.com/?id.230467 | Third Party Advisory |
Configurations
History
08 Jun 2023, 15:19
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://vuldb.com/?ctiid.230467 - Third Party Advisory | |
References | (MISC) https://vuldb.com/?id.230467 - Third Party Advisory | |
References | (MISC) https://gitee.com/gouguopen/office/issues/I74ZPU - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CPE | cpe:2.3:a:gougucms:pythagorean_oa_office_system:*:*:*:*:*:*:*:* |
01 Jun 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-01 14:15
Updated : 2024-05-17 02:27
NVD link : CVE-2023-3035
Mitre link : CVE-2023-3035
CVE.ORG link : CVE-2023-3035
JSON object : View
Products Affected
gougucms
- pythagorean_oa_office_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')