CVE-2023-48858

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via the login.php? URL part.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:abocms:abo.cms:5.9:*:*:*:*:*:*:*

History

21 Nov 2024, 08:32

Type Values Removed Values Added
References () https://abocms.ru/about/versions/version59/ - Release Notes () https://abocms.ru/about/versions/version59/ - Release Notes
References () https://github.com/Shumerez/CVE-2023-48858 - Exploit, Third Party Advisory () https://github.com/Shumerez/CVE-2023-48858 - Exploit, Third Party Advisory

24 Jan 2024, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
References () https://github.com/Shumerez/CVE-2023-48858 - () https://github.com/Shumerez/CVE-2023-48858 - Exploit, Third Party Advisory
References () https://abocms.ru/about/versions/version59/ - () https://abocms.ru/about/versions/version59/ - Release Notes
CPE cpe:2.3:a:abocms:abo.cms:5.9:*:*:*:*:*:*:*

18 Jan 2024, 13:42

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-17 20:15

Updated : 2024-11-21 08:32


NVD link : CVE-2023-48858

Mitre link : CVE-2023-48858

CVE.ORG link : CVE-2023-48858


JSON object : View

Products Affected

abocms

  • abo.cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')