CVE-2023-53910
MEDIUMWBCE CMS 1.6.1 - Authenticated Stored Cross-Site Scripting via Page Content
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53910. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary The exploit demonstrates two stored XSS vulnerabilities in WBCE CMS 1.6.1: one via SVG file upload and another via page content injection. Both include detailed steps, payloads, and HTTP requests to trigger the XSS.
Description
WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script content in the content parameter to execute JavaScript when users view the affected page.
Exploits (1)
The exploit demonstrates two stored XSS vulnerabilities in WBCE CMS 1.6.1: one via SVG file upload and another via page content injection. Both include detailed steps, payloads, and HTTP requests to trigger the XSS.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N