CVE-2023-31434

MEDIUM

evasys <8.2.2286 & <9.0.2401 - XSS

Title source: llm
STIX 2.1

Description

The parameters nutzer_titel, nutzer_vn, and nutzer_nn in the user profile, and langID and ONLINEID in direct links, in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 do not validate input, which allows authenticated attackers to inject HTML Code and XSS payloads in multiple locations.

Exploits (1)

nomisec WRITEUP
by trustcves · poc
https://github.com/trustcves/CVE-2023-31434

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://cves.at/posts/cve-2023-31434/writeup/

Scores

CVSS v3 5.4
EPSS 0.0033
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
evasys/evasys 8.2
evasys/evasys 9.0
Published May 02, 2023
Tracked Since Feb 18, 2026