CVE-2023-43344
MEDIUMQuick CMS 6.7 - Stored Cross-Site Scripting via SEO Meta Description Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-43344. PoCs published by sromanhu.
AI-analyzed exploit summary This repository documents a stored XSS vulnerability in Quick CMS v6.7, where the SEO Meta description field fails to sanitize input, allowing arbitrary JavaScript execution. The writeup includes technical details, payload examples, and screenshots demonstrating the exploit.
Description
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the SEO - Meta description parameter in the Pages Menu component.
Exploits (1)
This repository documents a stored XSS vulnerability in Quick CMS v6.7, where the SEO Meta description field fails to sanitize input, allowing arbitrary JavaScript execution. The writeup includes technical details, payload examples, and screenshots demonstrating the exploit.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N