PT-2024-12147 · Easyxdm · Easyxdm

Saad Alfakir

·

Published

2024-01-08

·

Updated

2024-01-12

·

CVE-2023-27739

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions easyXDM version 2.5
Description The issue allows for cross-site scripting (XSS) attacks via the xdm e parameter. This means an attacker could potentially inject malicious scripts into a website, affecting users who visit the site.
Recommendations For easyXDM version 2.5, consider restricting access to the xdm e parameter to minimize the risk of exploitation until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-27739

Affected Products

Easyxdm