Record summary

CVE-2023-40752 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMPHPJabbers Make an Offer Widget v1.0 - Cross-Site ScriptingCVSS 6.1

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

Impact

Unauthenticated attackers can inject malicious JavaScript through the action parameter, potentially stealing session cookies and executing actions on behalf of users interacting with the Make an Offer Widget.

Remediation

Update PHPJabbers Make an Offer Widget to a version newer than 1.0 that properly sanitizes the action parameter and encodes output to prevent XSS attacks.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023phpjabbersmake-an-offer-widgetxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phpjabbers:make_an_offer_widget:1.0:*:*:*:*:*:*:*
Shodan: html:"PHPJabbers"
FOFA: body="PHPJabbers"

Source: ProjectDiscovery

References

4