PT-2023-29023 · Ritecms · Ritecms

Sergio

·

Published

2023-09-28

·

Updated

2023-09-29

·

CVE-2023-43878

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rite CMS version 3.0
Description The issue allows attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu. This is a result of Multiple Cross-Site scripting (XSS) vulnerabilities.
Recommendations For Rite CMS version 3.0, consider disabling access to the Administration Menu until a patch is available to prevent exploitation of the XSS vulnerabilities. Restrict the ability to add or modify Main Menu Items to minimize the risk of arbitrary code execution.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-43878

Affected Products

Ritecms