CVE-2023-37153
CVSS 3.1 Score 6.1 of 10 (medium)
Attack Complexity low
Scope changed
Confidentiality low
Integrity low
Availability none
Privileges Required none
Details
Published Jul 10, 2023
Updated: Aug 2, 2023
CWE ID 79
Summary
CVE-2023-37153 is a newly discovered Cross-Site Scripting (XSS) vulnerability affecting KodExplorer version 4.51. This issue resides in the Description box of the Light App creation feature. An attacker can leverage this flaw by injecting malicious XSS code into the Description field, potentially gaining unauthorized access to users' data or taking control of their sessions. This vulnerability poses a significant risk to users, emphasizing the importance of keeping software up-to-date with security patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share