CVE-2023-43323

MEDIUM NUCLEI

mooSocial 3.1.8 - SSRF

Title source: llm

Description

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

Exploits (1)

nomisec WORKING POC 1 stars
by ahrixia · poc
https://github.com/ahrixia/CVE-2023-43323

Nuclei Templates (1)

mooSocial 3.1.8 - External Service Interaction
MEDIUMby ritikchaddha
Shodan: http.favicon.hash:702863115clear
FOFA: mooSocial || moosocial || icon_hash="702863115"

Scores

CVSS v3 6.5
EPSS 0.8080
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-15
Status published
Products (1)
moosocial/moosocial 3.1.8
Published Sep 28, 2023
Tracked Since Feb 18, 2026