PT-2023-29023 · Ritecms · Ritecms

Sergio

·

Publicado

2023-09-28

·

Atualizado

2023-09-29

·

CVE-2023-43878

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rite CMS version 3.0
Description The issue allows attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu. This is a result of Multiple Cross-Site scripting (XSS) vulnerabilities.
Recommendations For Rite CMS version 3.0, consider disabling access to the Administration Menu until a patch is available to prevent exploitation of the XSS vulnerabilities. Restrict the ability to add or modify Main Menu Items to minimize the risk of arbitrary code execution.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-43878

Produtos afetados

Ritecms