CVE-2023-3849

LOW NUCLEI

mooSocial mooDating 1.2 - Cross-Site Scripting in URL Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-3849. PoCs published by CraCkEr. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates reflected XSS vulnerabilities in mooDating 1.2 by injecting malicious payloads into URL parameters across multiple endpoints. The payloads trigger JavaScript execution via crafted URLs, potentially leading to session hijacking or credential theft.

Description

A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. Affected is an unknown function of the file /find-a-match of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-235200. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

Exploits (1)

exploitdb WORKING POC
by CraCkEr · textwebappsphp
https://www.exploit-db.com/exploits/51628

This exploit demonstrates reflected XSS vulnerabilities in mooDating 1.2 by injecting malicious payloads into URL parameters across multiple endpoints. The payloads trigger JavaScript execution via crafted URLs, potentially leading to session hijacking or credential theft.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: mooDating 1.2
No auth needed
Prerequisites: Victim interaction (clicking a malicious link)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

mooDating 1.2 - Cross-site scripting
MEDIUMVERIFIEDby r3Y3r53

References (3)

Core 3
Core References
Third Party Advisory vdb-entry
https://vuldb.com/?id.235200
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.235200

Scores

CVSS v3 3.5
EPSS 0.0368
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
moosocial/moodating 1.2
Published Jul 23, 2023
Tracked Since Feb 18, 2026