Vulnerability Details CVE-2023-25295
A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-25295
-
cpe:2.3:a:gruen:evewa3:31
-
cpe:2.3:a:gruen:evewa3:53