Cross-Site Scripting Vulnerability in ImpressCMS by CrownZTX
CVE-2023-37785
4.8MEDIUM
What is CVE-2023-37785?
A cross-site scripting (XSS) vulnerability exists in ImpressCMS versions prior to 1.4.5. This flaw allows attackers to exploit the application by injecting malicious scripts into the smile_code parameter within the /editprofile.php component. As a result, attackers can execute arbitrary web scripts or HTML in the context of the end user's browser, potentially leading to unauthorized actions or data breaches.
