Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form.
References
Link | Resource |
---|---|
https://github.com/boxbilling/boxbilling/issues/596 | Exploit Issue Tracking |
https://github.com/boxbilling/boxbilling/issues/596 | Exploit Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
31 Jan 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/boxbilling/boxbilling/issues/596 - Exploit, Issue Tracking |
05 May 2023, 18:23
Type | Values Removed | Values Added |
---|---|---|
First Time |
Boxbilling
Boxbilling boxbilling |
|
CPE | cpe:2.3:a:boxbilling:boxbilling:4.20:*:*:*:*:*:*:* cpe:2.3:a:boxbilling:boxbilling:4.19:*:*:*:*:*:*:* cpe:2.3:a:boxbilling:boxbilling:4.21:*:*:*:*:*:*:* cpe:2.3:a:boxbilling:boxbilling:4.19.1:*:*:*:*:*:*:* |
|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
References | (MISC) https://github.com/boxbilling/boxbilling/issues/596 - Exploit, Issue Tracking |
28 Apr 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-28 20:15
Updated : 2025-01-31 18:15
NVD link : CVE-2020-23647
Mitre link : CVE-2020-23647
JSON object : View
Products Affected
boxbilling
- boxbilling
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')