Unknown · Phpkobo Ajaxnewticker · CVE-2023-41447
**Name of the Vulnerable Software and Affected Versions**
phpkobo AjaxNewTicker version 1.0.5
**Description**
A Cross Site Scripting issue allows a remote attacker to execute arbitrary code via a crafted payload to the `subcmd` parameter in the "index.php" component.
**Recommendations**
For phpkobo AjaxNewTicker version 1.0.5, consider disabling access to the `subcmd` parameter in the "index.php" component until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.