PT-2023-32331 · Unknown · Flusity-Cms
Zihe
·
Published
2023-10-26
·
Updated
2026-01-29
·
CVE-2023-5793
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
flusity CMS (affected versions not specified)
Description
A problematic issue has been identified in flusity CMS, affecting the
loadCustomBlocCreateForm function within the /core/tools/customblock.php file of the Dashboard component. Manipulation of the customblock place argument can lead to cross site scripting. The attack can be initiated remotely, and the exploit has been publicly disclosed.Recommendations
Apply the patch named 81252bc764e1de2422e79e36194bba1289e7a0a5 to resolve this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flusity-Cms