PT-2023-32331 · Unknown · Flusity-Cms

Zihe

·

Published

2023-10-26

·

Updated

2026-01-29

·

CVE-2023-5793

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions flusity CMS (affected versions not specified)
Description A problematic issue has been identified in flusity CMS, affecting the loadCustomBlocCreateForm function within the /core/tools/customblock.php file of the Dashboard component. Manipulation of the customblock place argument can lead to cross site scripting. The attack can be initiated remotely, and the exploit has been publicly disclosed.
Recommendations Apply the patch named 81252bc764e1de2422e79e36194bba1289e7a0a5 to resolve this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-5793

Affected Products

Flusity-Cms