CVE-2023-48858

MEDIUM

Armex ABO.CMS 5.9 - XSS

Title source: llm
STIX 2.1

Description

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via the login.php? URL part.

Exploits (1)

nomisec WORKING POC
by Shumerez · poc
https://github.com/Shumerez/CVE-2023-48858

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://github.com/Shumerez/CVE-2023-48858

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
abocms/abo.cms 5.9
Published Jan 17, 2024
Tracked Since Feb 18, 2026