CVE-2023-3849
LOW NUCLEImooSocial mooDating 1.2 - Cross-Site Scripting in URL Handler
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-3849. PoCs published by CraCkEr. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates reflected XSS vulnerabilities in mooDating 1.2 by injecting malicious payloads into URL parameters across multiple endpoints. The payloads trigger JavaScript execution via crafted URLs, potentially leading to session hijacking or credential theft.
Description
A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. Affected is an unknown function of the file /find-a-match of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-235200. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
Exploits (1)
This exploit demonstrates reflected XSS vulnerabilities in mooDating 1.2 by injecting malicious payloads into URL parameters across multiple endpoints. The payloads trigger JavaScript execution via crafted URLs, potentially leading to session hijacking or credential theft.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N