CVE-2023-4174 EXPLOIT
3.5
LOW · CVSS 3.1 · EPSS 9.1% (pctl 95)
Patch early
A public exploit exists.
Description
A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability.
Scoring
| CVSS | 3.5 (LOW, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 9.14% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-08-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| moosocial | moostore |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Social-Commerce 3.1.6 - Reflected XSS | 2023-08-08 |
References
- http://packetstormsecurity.com/files/174017/Social-Commerce-3.1.6-Cross-Site-Scripting.html
- https://vuldb.com/?ctiid.236209
- https://vuldb.com/?id.236209
- http://packetstormsecurity.com/files/174017/Social-Commerce-3.1.6-Cross-Site-Scripting.html
- https://vuldb.com/?ctiid.236209
- https://vuldb.com/?id.236209
→ the Explorer · watch your stack · NVD