PT-2025-51305 · Zomplog · Zomplog
Mirabbas Ağalarov
·
Published
2025-12-15
·
Updated
2025-12-24
·
CVE-2023-53887
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zomplog version 3.9
Description
The software contains a cross-site scripting issue that permits authenticated users to inject malicious scripts during the creation of new pages. An attacker can leverage crafted malicious image source and onerror attributes to execute arbitrary JavaScript code within a victim’s browser.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize all user-supplied input when creating new pages to prevent the injection of malicious scripts.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zomplog