PT-2023-31058 · Powercms · Powercms

CVE-2023-49117

·

Published

2023-12-25

·

Updated

2024-01-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PowerCMS versions 4 Series through 6 Series PowerCMS versions 3 Series and earlier
Description The issue is a stored cross-site scripting vulnerability. If exploited, an arbitrary script may be executed on a logged-in user's web browser.
Recommendations For PowerCMS versions 4 Series through 6 Series, update to a version that includes a fix for this issue. For PowerCMS versions 3 Series and earlier, since these versions are End-of-Life and no longer supported, consider upgrading to a supported version of PowerCMS to mitigate the risk of exploitation. As a temporary workaround, consider implementing input validation and sanitization to minimize the risk of arbitrary script execution.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49117

Affected Products

Powercms