Cross Site Scripting Vulnerability in wuzhicms by WuzhiCMS
CVE-2023-30123

5.4MEDIUM

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
28 April 2023

What is CVE-2023-30123?

The wuzhicms version 4.1.0 is susceptible to a Cross Site Scripting (XSS) vulnerability that can be exploited in the Member Center and Account Settings areas. Attackers can inject malicious scripts that may execute in the context of the user's browser, potentially leading to unauthorized access or data theft. This highlights the critical need for developers to implement robust input validation and output encoding to safeguard user data and system integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.