CVE-2023-48858

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via the login.php? URL part.
References
Link Resource
https://abocms.ru/about/versions/version59/ Release Notes
https://github.com/Shumerez/CVE-2023-48858 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:abocms:abo.cms:5.9:*:*:*:*:*:*:*

History

24 Jan 2024, 20:16

Type Values Removed Values Added
CPE cpe:2.3:a:abocms:abo.cms:5.9:*:*:*:*:*:*:*
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://abocms.ru/about/versions/version59/ - () https://abocms.ru/about/versions/version59/ - Release Notes
References () https://github.com/Shumerez/CVE-2023-48858 - () https://github.com/Shumerez/CVE-2023-48858 - Exploit, Third Party Advisory
First Time Abocms abo.cms
Abocms

18 Jan 2024, 13:42

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-17 20:15

Updated : 2024-01-24 20:16


NVD link : CVE-2023-48858

Mitre link : CVE-2023-48858

CVE.ORG link : CVE-2023-48858


JSON object : View

Products Affected

abocms

  • abo.cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')