CVE-2023-24278
MEDIUM NUCLEISquidex < 7.4.0 - Reflected Cross-Site Scripting via squid.svg Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-24278. PoCs published by NeCr00. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-24278, a reflected XSS vulnerability in Squidex versions prior to 7.4.0. It includes a proof-of-concept exploit demonstrating how malicious JavaScript can be injected via the `background` parameter of the `/squid.svg` endpoint.
Description
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2023-24278, a reflected XSS vulnerability in Squidex versions prior to 7.4.0. It includes a proof-of-concept exploit demonstrating how malicious JavaScript can be injected via the `background` parameter of the `/squid.svg` endpoint.
Nuclei Templates (1)
http.favicon.hash:1099097618
icon_hash=1099097618
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N