PT-2023-28780 · Moosocial · Moosocial
Ahrixia
·
Publicado
2023-09-27
·
Atualizado
2024-09-25
·
CVE-2023-43323
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mooSocial version 3.1.8
Description
The issue concerns external service interaction on the post function. When executed, the server sends HTTP and DNS requests to an external server. The parameters affected are multiple, including
messageText, data[wall photo], data[userShareVideo], and data[userShareLink].Recommendations
For mooSocial version 3.1.8, consider disabling the post function until a patch is available to prevent external service interaction. Restrict access to the parameters
messageText, data[wall photo], data[userShareVideo], and data[userShareLink] to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Moosocial