PT-2023-22510 · Unknown · Gis3W G3W-Suite
Jacopo Talamini
·
Published
2023-07-07
·
Updated
2023-07-14
·
CVE-2023-29998
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gis3W g3w-suite version 3.5
Description
A Cross-site scripting (XSS) vulnerability in the content editor allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the
description parameter.Recommendations
For Gis3W g3w-suite version 3.5, consider restricting access to the content editor to minimize the risk of exploitation until a patch is available. Avoid using the
description parameter in the affected content editor until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gis3W G3W-Suite