CVE-2023-2560

LOW

NewBingGoGo < 2023.5.5.2 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

A vulnerability was found in jja8 NewBingGoGo up to 2023.5.5.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228167.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.228167
Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.228167
Third Party Advisory exploit issue-tracking
https://gitee.com/jja8/NewBingGoGo/issues/I6WH2E

Scores

CVSS v3 3.5
EPSS 0.0025
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
newbinggogo_project/newbinggogo < 2023.5.5.2
Published May 06, 2023
Tracked Since Feb 18, 2026