Vulnerability Details CVE-2023-53887
Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source and onerror attributes to execute arbitrary JavaScript code in victim's browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.5%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2023-53887
-
cpe:2.3:a:zomp:zomplog:3.9