CVE-2023-2624
KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting
Record summary
CVE-2023-2624 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
KiviCareDefault status: unaffected | CVE List | Before 3.2.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMKiviCare WordPress Plugin - Cross-Site ScriptingCVSS 6.1
The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape the 'filterType' parameter, leading to Reflected Cross-Site Scripting.
Impact
Successful exploitation could allow an attacker to execute malicious scripts in the context of the victim's browser.
Remediation
Update to the latest version of the KiviCare WordPress Plugin to mitigate the XSS vulnerability.
Source: ProjectDiscovery