Cross-Site Scripting Vulnerability in Evolution CMS by Sromanhu
CVE-2023-43340
5.2MEDIUM
Key Information:
- Vendor
Evo
- Status
- Vendor
- CVE Published:
- 19 October 2023
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2023-43340?
A Cross-Site Scripting (XSS) vulnerability in Evolution CMS version 3.2.3 allows local attackers to inject arbitrary code. Exploitation can be achieved via crafted payloads injected into the cmsadmin, cmsadminemail, cmspassword, and cmspasswordconfim parameters. This vulnerability highlights the importance of secure coding practices and input validation to prevent malicious code execution.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
