PT-2026-2431 · Webgrind · Webgrind
Rafael Pedrero
·
Published
2026-01-13
·
Updated
2026-01-14
·
CVE-2023-54341
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webgrind versions 1.1 and earlier
Description
The application does not adequately encode user-supplied data, enabling unauthenticated attackers to inject malicious scripts through the
file parameter in the 'index.php' file. This allows attackers to execute arbitrary JavaScript in a victim’s browser by creating malicious URLs. The affected API endpoint is 'index.php'. The vulnerable parameter is file.Recommendations
Versions prior to 1.1 should be updated.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webgrind