CVE-2023-41863
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Sep 25, 2023
Updated: Sep 26, 2023
CWE ID 79
Summary
CVE-2023-41863 is a newly discovered vulnerability affecting the PeproDev CF7 Database plugin, versions 1.7.0 and below, developed by Pepro Dev. Group. This issue involves an unauthenticated Stored Cross-Site Scripting (XSS) weakness. An attacker can exploit this flaw by injecting malicious scripts into a targeted website's database, enabling them to execute arbitrary code and potentially take control of user sessions. The vulnerability poses a significant risk to websites that have not yet updated their plugin to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share