PT-2023-29317 · Unknown · Easy Address Book Web Server

Rafael Pedrero

·

Published

2023-10-04

·

Updated

2023-10-06

·

CVE-2023-4492

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Easy Address Book Web Server version 1.6
Description The issue affects the parameters firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, and workzip of the "/addrbook.ghp" file, allowing an attacker to inject a JavaScript payload designed to run when the application is loaded.
Recommendations For Easy Address Book Web Server version 1.6, consider disabling the parameters firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, and workzip in the "/addrbook.ghp" file as a temporary workaround until a patch is available. Restrict access to the "/addrbook.ghp" file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-4492

Affected Products

Easy Address Book Web Server