CVE-2023-3843
LOW NUCLEImooSocial mooDating 1.2 - Cross-Site Scripting in URL Handler
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-3843. A Nuclei detection template is also available.
AI-analyzed exploit summary The exploit demonstrates reflected XSS (RXSS) vulnerabilities in mooDating 1.2 by providing multiple malicious URLs targeting different endpoints. Each URL injects an XSS payload via URL parameters, triggering JavaScript execution in the victim's browser.
Description
A vulnerability was found in mooSocial mooDating 1.2. It has been classified as problematic. Affected is an unknown function of the file /matchmakings/question of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-235194 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
Exploits (1)
The exploit demonstrates reflected XSS (RXSS) vulnerabilities in mooDating 1.2 by providing multiple malicious URLs targeting different endpoints. Each URL injects an XSS payload via URL parameters, triggering JavaScript execution in the victim's browser.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N