PT-2023-28780 · Moosocial · Moosocial
Ahrixia
·
Published
2023-09-27
·
Updated
2024-09-25
·
CVE-2023-43323
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mooSocial version 3.1.8
Description
The issue concerns external service interaction on the post function. When executed, the server sends HTTP and DNS requests to an external server. The parameters affected are multiple, including
messageText, data[wall photo], data[userShareVideo], and data[userShareLink].Recommendations
For mooSocial version 3.1.8, consider disabling the post function until a patch is available to prevent external service interaction. Restrict access to the parameters
messageText, data[wall photo], data[userShareVideo], and data[userShareLink] to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moosocial