Cross Site Scripting Vulnerability in DiscuzX 3.4 by Discuz
CVE-2022-45543

6.1MEDIUM

Key Information:

Vendor

Discuz

Status
Vendor
CVE Published:
15 February 2023

What is CVE-2022-45543?

The Cross Site Scripting vulnerability in DiscuzX 3.4 allows attackers to craft malicious input through parameters such as datetline, title, tpp, or username during the audit search process. This flaw can lead to the execution of arbitrary code in the context of affected users' browsers, potentially compromising sensitive information and leading to unauthorized actions by the attacker. Organizations using DiscuzX 3.4 are advised to review their implementations and apply necessary security measures to mitigate this risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.