CVE-2023-34423
CVE-2023-34423
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
03 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
AYS Pro Plugins · Survey MakerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →