packetstormsecurity.com
http://packetstormsecurity.com/files/171734/Provide-Server-14.4-XSS-Cross-Site-Request-Forgery-Code-Execution.html CVE-2023-23286
MEDIUM
Provide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)
Record summary
CVE-2023-23286 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBProvide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)ExploitDB exploitby Andreas FinstadNot analyzed1 file
References
4f20.be
https://f20.be/cves/provide-server-v-14-4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-23286 provideserver.se
https://www.provideserver.se/