PT-2024-14301 · Ofcms · Ofcms

Phantom4Me

·

Published

2024-01-16

·

Updated

2024-01-23

·

CVE-2023-51807

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OFCMS version 1.14
Description A Cross Site Scripting issue allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component. This enables the attacker to execute malicious scripts, potentially leading to unauthorized access or data breaches.
Recommendations For OFCMS version 1.14, consider disabling the title addition component until a patch is available to prevent exploitation. Restrict access to sensitive information and monitor for suspicious activity. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51807

Affected Products

Ofcms