PT-2023-25004 · Unknown · Simplephpscripts Guestbook Script

·

CVE-2023-3476

·

Publicado

2023-06-30

·

Atualizado

2024-05-17

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SimplePHPscripts GuestBook Script version 2.2
Description A vulnerability was found in the SimplePHPscripts GuestBook Script, affecting an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely.
Recommendations For SimplePHPscripts GuestBook Script version 2.2, it is recommended to upgrade the affected component. As a temporary workaround, consider restricting access to the preview.php file until a patch is available. Avoid using the vulnerable URL Parameter Handler component in the preview.php file until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3476

Produtos afetados

Simplephpscripts Guestbook Script