Record summary

CVE-2023-40755 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMPHPJabbers Callback Widget v1.0 - Cross-Site ScriptingCVSS 6.1

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

Impact

Unauthenticated attackers can inject malicious JavaScript through the theme parameter in preview.php, potentially stealing callback widget administrator credentials and manipulating callback requests.

Remediation

Update PHPJabbers Callback Widget to a version newer than 1.0 that properly sanitizes the theme parameter and encodes output in preview.php.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023phpjabberscallback-widgetxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phpjabbers:callback_widget:1.0:*:*:*:*:*:*:*
Shodan: html:"PHPJabbers"
FOFA: body="PHPJabbers"

Source: ProjectDiscovery

References

4