CVE-2023-37164
MEDIUMDiafan.cms - XSS
Title source: ruleDescription
Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by tmrswrr · textwebappsphp
https://www.exploit-db.com/exploits/51529
Scores
CVSS v3
6.1
EPSS
0.0044
EPSS Percentile
63.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
diafan/diafan.cms
6.0
Published
Jul 20, 2023
Tracked Since
Feb 18, 2026