Reflected Cross-Site Scripting in Jorani by Jorani
CVE-2023-53870
Key Information:
Badges
What is CVE-2023-53870?
The Jorani application version 1.0.3 is susceptible to a reflected cross-site scripting vulnerability due to insufficient validation of the 'language' parameter. This flaw allows an attacker to craft malicious scripts that can be executed within the user's browser, leading to unauthorized access to sensitive information such as user sessions. Attackers can exploit this vulnerability to manipulate user interactions and potentially compromise the security of the application.
Affected Version(s)
Jorani 1.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
