PT-2023-17137 · Otcms · Otcms

Fzh1613

·

Publicado

2023-03-25

·

Atualizado

2024-05-17

·

CVE-2023-1635

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OTCMS version 6.72
Description A vulnerability was found in the function AutoRun of the file apiRun.php. The manipulation of the argument mode leads to cross-site scripting. The attack can be launched remotely.
Recommendations For OTCMS version 6.72, consider disabling the AutoRun function of the apiRun.php file until a patch is available. Restrict access to the apiRun.php file to minimize the risk of exploitation. Avoid using the mode argument in the affected function until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1635

Produtos afetados

Otcms