Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Whj_Jinqu

#43386de 53,635
6.1CVSS total
Vulnerabilidades · 1
PT-2023-21852
6.1
2023-05-24
Unknown · Siteserver Cms · CVE-2023-2862
**Name of the Vulnerable Software and Affected Versions** SiteServer CMS versions up to 7.2.1 **Description** A problematic issue was found in the software, affecting an unknown function of the file /api/stl/actions/search. The manipulation of the `ajaxDivId` argument leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. **Recommendations** For versions up to 7.2.1, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the `/api/stl/actions/search` endpoint or avoiding the use of the `ajaxDivId` argument until a patch is available.