CVE-2023-53906
MEDIUMprojectSend r1605 - Authenticated Stored Cross-Site Scripting via Custom Assets Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53906. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in projectSend r1605. The attacker injects malicious JavaScript via the custom assets feature, which executes when victims visit the homepage.
Description
projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in projectSend r1605. The attacker injects malicious JavaScript via the custom assets feature, which executes when victims visit the homepage.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N