CVE-2023-41446
MEDIUMphpkobo AjaxNewTicker 1.0.5 - Cross-Site Scripting via Title Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-41446. PoCs published by CyKingx.
AI-analyzed exploit summary This PoC demonstrates a reflected Cross-Site Scripting (XSS) vulnerability in phpkobo AjaxNewsTicker v1.05 via the 'title' parameter in the admin panel. The exploit includes both POST and GET request methods to inject malicious JavaScript payloads, which execute when a victim interacts with the crafted news title.
Description
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
Exploits (1)
This PoC demonstrates a reflected Cross-Site Scripting (XSS) vulnerability in phpkobo AjaxNewsTicker v1.05 via the 'title' parameter in the admin panel. The exploit includes both POST and GET request methods to inject malicious JavaScript payloads, which execute when a victim interacts with the crafted news title.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N