NA

CVE-2023-4493

Published: 04/10/2023 Updated: 06/10/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects multiple parameters such as (firstname, homephone, lastname, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, workzip). This vulnerability allows a remote malicious user to store a malicious JavaScript payload in the application to be executed when the page is loaded, resulting in an integrity impact.

Vulnerable Product Search on Vulmon Subscribe to Product

easy address book web server project easy address book web server 1.6

Exploits

Easy Address Book Web Server version 16 suffers from buffer overflow and cross site scripting vulnerabilities ...