Cross-Site Scripting Vulnerability in Evolution CMS by Sromanhu
CVE-2023-43340

5.2MEDIUM

Key Information:

Vendor

Evo

Vendor
CVE Published:
19 October 2023

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2023-43340?

A Cross-Site Scripting (XSS) vulnerability in Evolution CMS version 3.2.3 allows local attackers to inject arbitrary code. Exploitation can be achieved via crafted payloads injected into the cmsadmin, cmsadminemail, cmspassword, and cmspasswordconfim parameters. This vulnerability highlights the importance of secure coding practices and input validation to prevent malicious code execution.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability Reserved

.