CVE-2023-24278
Squidex <7.4.0 - Cross-Site Scripting
Record summary
CVE-2023-24278 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
Exploitation context
Proofs of concept
1Repository PoCs
GitHubNeCr00/CVE-2023-24278Repository PoCby NeCr00Stars: 7Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMSquidex <7.4.0 - Cross-Site ScriptingCVSS 6.1
Squidex before 7.4.0 contains a cross-site scripting vulnerability via the squid.svg endpoint. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to Squidex CMS version 7.4.0 or later to mitigate this vulnerability.
Source: ProjectDiscovery