CVE-2023-7259

CVSS v3 Score
2.4
Low
CVSS v2 Score
3.3
Low

Vulnerability Description

** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-266127. NOTE: The vendor rejected the issue because he claims that XSS which require administrative privileges are not of any use for attackers.

CVSS:2.4(Low)

Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the v...

CWE-792019
CVSS:2.4(Low)

Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.

CWE-792022
CVSS:2.4(Low)

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.

CWE-792023
CVSS:2.4(Low)

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Pag...

CWE-792024
CVSS:2.4(Low)

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component...

CWE-792024
CVSS:2.4(Low)

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. T...

CWE-792024
leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-266127. NOTE: The vendor rejected the issue because he claims that XSS which require administrative privileges are not of any use for attackers." } }, { "@type": "Question", "name": "How severe is CVE-2023-7259?", "acceptedAnswer": { "@type": "Answer", "text": "This vulnerability has a severity rating of MEDIUM with a CVSS score of 2.4 out of 10." } }, { "@type": "Question", "name": "What type of vulnerability is CVE-2023-7259?", "acceptedAnswer": { "@type": "Answer", "text": "This is classified as CWE-79, which is a common weakness in software security." } } ] }