CVE-2023-3465
Last modified
CVE-2023-3465 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-232711.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Simplephpscripts | Classified Ads Script Php | 1.8 |
References
- https://vuldb.com/?ctiid.232711Permissions Required, Third Party Advisory
- https://vuldb.com/?id.232711Third Party Advisory
- https://vuldb.com/?ctiid.232711Permissions Required, Third Party Advisory
- https://vuldb.com/?id.232711Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3465?
How severe is CVE-2023-3465?
How do I fix CVE-2023-3465?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-34641KioWare for Windows through v8.33 was discovered to contain …7.8
- CVE-2023-34642KioWare for Windows through v8.33 was discovered to contain …7.8
- CVE-2023-34644Remote code execution vulnerability in Ruijie Networks Produ…9.8
- CVE-2023-34645jfinal CMS 5.1.0 has an arbitrary file read vulnerability.7.5
- CVE-2023-34647PHPgurukl Hostel Management System v.1.0 is vulnerable to Cr…6.1
- CVE-2023-34648A Cross Site Scripting vulnerability in PHPgurukl User Regis…6.1
- CVE-2023-34650PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Script…6.1
- CVE-2023-34651PHPgurukl Hospital Management System v.1.0 is vulnerable to …6.1
- CVE-2023-34652PHPgurukl Hostel Management System v.1.0 is vulnerable to Cr…6.1
- CVE-2023-34654taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).6.1
- CVE-2023-34656An issue was discovered with the JSESSION IDs in Xiamen Si X…8.8
- CVE-2023-34657A stored cross-site scripting (XSS) vulnerability in Eyoucms…4.8
Are you affected by CVE-2023-3465?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
