Record summary

CVE-2023-2023 has a selected CVSS score of 6.1 (medium); EIP currently links 27 repository PoCs and 1 Nuclei template.

Description

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
27
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 9, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Custom 404 Pro

Default status: unaffected

CVE ListBefore 3.7.3affected

Proofs of concept

Showing 12 of 27

Repository PoCs

GitHubabrahim7112/hackers_CVE_2023_pocRepository PoCby abrahim7112Stars: 12Not analyzed342 files

4.1 MiB

GitHub

PoC details
GitHubthatformat/Hvv2023Repository PoCby thatformatStars: 5Not analyzed120 files

3.3 MiB

GitHub

PoC details
GitHubamirzargham/CVE-2023-08-21-exploitRepository PoCby amirzarghamStars: 1Not analyzed2 files

4.6 KiB

GitHub

PoC details
GitHubamirzargham/CVE-2023-0099-exploitRepository PoCby amirzarghamStars: 6Not analyzed2 files

3.4 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubtarihub/blackjumpRepository PoCby tarihubStars: 276Not analyzed9 files

259.7 KiB · linked to 3 vulnerabilities

GitHub

PoC details
GitHubteam890/CVE-2023-2024Repository PoCby team890Stars: 1Not analyzed75 files

3.7 MiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubChocapikk/CVE-2023-6553Repository PoCby ChocapikkStars: 86Not analyzed4 files

21.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubpentestfunctions/BlueDuckyRepository PoCby pentestfunctionsStars: 1,886Not analyzed16 files

845.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubrockrid3r/CVE-2023-5178Repository PoCby rockrid3rStars: 7Not analyzed12 files

697.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubtianstcht/CVE-2023-4427Repository PoCby tianstchtStars: 28Not analyzed3 files

10.4 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubnles-crt/CVE-2023-6895Repository PoCby nles-crtStars: 0Not analyzed2 files

3.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details
GitHubuser0x1337/CVE-2023-30547Repository PoCby user0x1337Stars: 0Not analyzed4 files

23.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Search the exploit catalog for CVE-2023-2023

Nuclei templates

1
ProjectDiscoveryMEDIUMCustom 404 Pro < 3.7.3 - Cross-Site ScriptingCVSS 6.1

Custom 404 Pro before 3.7.3 is susceptible to cross-site scripting via the search parameter due to insufficient input sanitization and output escaping. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Fixed in version 3.7.3

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2023cvewpscanxsswordpresswp-pluginauthenticatedcustom-404-prointrusivekunalnagarvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:kunalnagar:custom_404_pro:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2