CVE-2023-3844
LOW NUCLEImooSocial mooDating 1.2 - Cross-Site Scripting in URL Handler
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-3844. A Nuclei detection template is also available.
AI-analyzed exploit summary The exploit demonstrates multiple reflected XSS vulnerabilities in mooDating 1.2 by providing crafted URLs with malicious payloads. The payloads inject JavaScript via the URL path, which executes when the victim visits the link.
Description
A vulnerability was found in mooSocial mooDating 1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /friends of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235195. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
Exploits (1)
The exploit demonstrates multiple reflected XSS vulnerabilities in mooDating 1.2 by providing crafted URLs with malicious payloads. The payloads inject JavaScript via the URL path, which executes when the victim visits the link.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N