Record summary

CVE-2023-39676 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMPrestaShop fieldpopupnewsletter Module - Cross Site ScriptingCVSS 6.1

Fieldpopupnewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential theft of sensitive information, session hijacking, or defacement.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-79
Authorsmeme-lord
Template tagscve2023cveprestashopxssfieldthemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fieldthemes:fieldpopupnewsletter:1.0.0:*:*:*:*:prestashop:*:*
Shodan: html:"fieldpopupnewsletter"
Shodan: http.html:"fieldpopupnewsletter"
FOFA: body="fieldpopupnewsletter"

Source: ProjectDiscovery

References

4