CVE-2023-4174

A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability.
References
Link Resource
http://packetstormsecurity.com/files/174017/Social-Commerce-3.1.6-Cross-Site-Scripting.html Exploit Third Party Advisory
https://vuldb.com/?ctiid.236209 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.236209 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:moosocial:moostore:3.1.6:*:*:*:*:*:*:*

History

29 Feb 2024, 01:41

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en mooSocial mooStore v3.1.6 y se ha clasificado como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida. La manipulación conduce a Cross-Site Scripting (XSS). El ataque puede lanzarse de forma remota. Se ha asignado a esta vulnerabilidad el identificador VDB-236209.

09 Aug 2023, 16:21

Type Values Removed Values Added
CPE cpe:2.3:a:moosocial:moostore:3.1.6:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References (MISC) http://packetstormsecurity.com/files/174017/Social-Commerce-3.1.6-Cross-Site-Scripting.html - (MISC) http://packetstormsecurity.com/files/174017/Social-Commerce-3.1.6-Cross-Site-Scripting.html - Exploit, Third Party Advisory
References (MISC) https://vuldb.com/?ctiid.236209 - (MISC) https://vuldb.com/?ctiid.236209 - Permissions Required, Third Party Advisory, VDB Entry
References (MISC) https://vuldb.com/?id.236209 - (MISC) https://vuldb.com/?id.236209 - Third Party Advisory, VDB Entry

07 Aug 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/174017/Social-Commerce-3.1.6-Cross-Site-Scripting.html -

06 Aug 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-06 01:15

Updated : 2024-05-17 02:31


NVD link : CVE-2023-4174

Mitre link : CVE-2023-4174

CVE.ORG link : CVE-2023-4174


JSON object : View

Products Affected

moosocial

  • moostore
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')