Record summary

CVE-2023-40753 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMPHPJabbers Ticket Support Script v3.2 - Cross-Site ScriptingCVSS 5.4

There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

Impact

Authenticated attackers can inject malicious JavaScript through the message parameter in ticket notifications, potentially stealing support staff session cookies and accessing sensitive customer support tickets.

Remediation

Update PHPJabbers Ticket Support Script to a version newer than 3.2 that properly sanitizes the message parameter and encodes output in notifications.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023phpjabbersticket-support-scriptxssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phpjabbers:ticket_support_script:3.2:*:*:*:*:*:*:*
Shodan: html:"PHPJabbers"
FOFA: body="PHPJabbers"

Source: ProjectDiscovery

References

4