CVE-2023-41446

MEDIUM

phpkobo AjaxNewTicker 1.0.5 - Cross-Site Scripting via Title Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-41446. PoCs published by CyKingx.

AI-analyzed exploit summary This PoC demonstrates a reflected Cross-Site Scripting (XSS) vulnerability in phpkobo AjaxNewsTicker v1.05 via the 'title' parameter in the admin panel. The exploit includes both POST and GET request methods to inject malicious JavaScript payloads, which execute when a victim interacts with the crafted news title.

Description

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.

Exploits (1)

github WORKING POC
by CyKingx · poc
https://github.com/CyKingx/cve/tree/main/CVE-2023-41446

This PoC demonstrates a reflected Cross-Site Scripting (XSS) vulnerability in phpkobo AjaxNewsTicker v1.05 via the 'title' parameter in the admin panel. The exploit includes both POST and GET request methods to inject malicious JavaScript payloads, which execute when a victim interacts with the crafted news title.

Classification
Working Poc 98%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: phpkobo AjaxNewsTicker 1.05
Auth required
Prerequisites: Attacker must have access to the admin panel (authenticated session) · Victim must click on or interact with the malicious news title
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →

References (3)

Core 3
Core References
Broken Link, Product
http://ajaxnewsticker.com

Scores

CVSS v3 6.1
EPSS 0.0058
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
phpkobo/ajaxnewsticker 1.0.5
Published Sep 28, 2023
Tracked Since Feb 18, 2026