CVE-2023-36121

Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
Configurations

Configuration 1 (hide)

cpe:2.3:a:e107:e107:2.3.2:*:*:*:*:*:*:*

History

05 Aug 2023, 03:55

Type Values Removed Values Added
First Time E107 e107
E107
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:e107:e107:2.3.2:*:*:*:*:*:*:*
References (MISC) https://www.chtsecurity.com/news/6c6675d4-3254-46ce-a16d-26523ff80540 - (MISC) https://www.chtsecurity.com/news/6c6675d4-3254-46ce-a16d-26523ff80540 - Third Party Advisory
References (MISC) https://www.chtsecurity.com/news/0a4743a5-491e-4685-95ee-df8316ab5284 - (MISC) https://www.chtsecurity.com/news/0a4743a5-491e-4685-95ee-df8316ab5284 - Exploit, Third Party Advisory
References (MISC) https://www.exploit-db.com/exploits/51449 - (MISC) https://www.exploit-db.com/exploits/51449 - Exploit, Third Party Advisory, VDB Entry
References (MISC) https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/e107%20v2.3.2.md - (MISC) https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/e107%20v2.3.2.md - Exploit, Third Party Advisory

02 Aug 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-02 00:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-36121

Mitre link : CVE-2023-36121

CVE.ORG link : CVE-2023-36121


JSON object : View

Products Affected

e107

  • e107
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')