icon

We found results for “

CVE-2023-46394

Good to know:

icon

Date: October 26, 2023

A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version hsk99/push-service - no_fix;zoujingli/think-plugs-static - v1.0.57;zoujingli/think-plugs-static - v1.0.74;hsk99/transfer-statistics - no_fix;jiannei/layadmin - v2.3.1;jiannei/layadmin - dev-analysis-1bMmEv;jiannei/layadmin - dev-analysis-QMgx2p;jiannei/layadmin - dev-analysis-bQnBn4;taoser/taoler - v2.3.6;taoser/taoler - dev-dependabot/composer/phpmailer/phpmailer-6.4.1;taoser/taoler - v1.9.15;taoser/taoler - no_fix;funadmin/funadmin - v5.x-dev;funadmin/funadmin - v2.1.0;funadmin/funadmin - dev-remotes/origin/v3.0;colasoft/colaphp - v1.0.0;HaveMvc.Web - no_fix;jiannei/pear-admin - v1.0.0;hsk99/webman-admin - no_fix;org.webjars:layui:2.8.12;org.webjars.npm:layui:2.8.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us