CVE-2023-48858

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via the login.php? URL part.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:abocms:abo.cms:5.9:*:*:*:*:*:*:*

History

24 Jan 2024, 20:16

Type Values Removed Values Added
References () https://abocms.ru/about/versions/version59/ - () https://abocms.ru/about/versions/version59/ - Release Notes
References () https://github.com/Shumerez/CVE-2023-48858 - () https://github.com/Shumerez/CVE-2023-48858 - Exploit, Third Party Advisory
CPE cpe:2.3:a:abocms:abo.cms:5.9:*:*:*:*:*:*:*
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Abocms abo.cms
Abocms

17 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-17 20:15

Updated : 2025-06-02 15:15


NVD link : CVE-2023-48858

Mitre link : CVE-2023-48858


JSON object : View

Products Affected

abocms

  • abo.cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')