6.1
CVSSv3

CVE-2023-38910

Published: 18/08/2023 Updated: 22/08/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows malicious users to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.

Vulnerable Product Search on Vulmon Subscribe to Product

cszcms csz cms 1.3.0

Exploits

CSZ CMS version 130 suffers from multiple persistent cross site scripting vulnerabilities ...