CVE-2023-43340

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-43340
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-43340.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-43340
Aliases
Published
2023-10-19T23:15:08Z
Modified
2024-10-12T11:06:17.819692Z
Severity
  • 5.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters

References

Affected packages

Git / github.com/evolution-cms/evolution

Affected ranges

Type
GIT
Repo
https://github.com/evolution-cms/evolution
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*

1.3.0
1.3.0b
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.0.RC
1.4.0.RC2
1.4.0.RC3
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5

2.*

2.0
2.0.0-RC
2.0.0-alpha
2.0.1
2.0.2

3.*

3.0
3.0.1
3.0.2
3.0RC
3.0RC2
3.0RC3
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.2
3.2.3