peter bassill · operator
$ cve CVE-2023-4174 JSON

CVE-2023-4174 EXPLOIT

3.5
LOW · CVSS 3.1 · EPSS 9.1% (pctl 95)

Patch early

A public exploit exists.

Description

A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability.

Scoring

CVSS3.5 (LOW, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
EPSS9.14% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2023-08-06
Last modified2026-06-17

Affected (1)

VendorProduct
moosocialmoostore

Public exploits

SourceTitleDate
exploit-dbSocial-Commerce 3.1.6 - Reflected XSS2023-08-08

References

→ the Explorer  ·  watch your stack  ·  NVD