Cross Site Scripting Vulnerability in PHPJabbers Callback Widget
CVE-2023-36314
6.1MEDIUM
What is CVE-2023-36314?
A Cross Site Scripting (XSS) vulnerability exists within the value-text-o_sms_email_request_message parameters of the index.php file in PHPJabbers Callback Widget version 1.0. This vulnerability allows attackers to inject malicious scripts into the web application, potentially leading to data theft, credential compromise, and unauthorized access. Users of the affected product should prioritize updating to a secure version and reviewing their web security practices to mitigate potential attacks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved