07FLY CRM har 1.2.0 User Profile Cross Site Scripting

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a 07FLY CRM har 1.2.0. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil $software_file, a cikin sashen User Profile Handler. A sa manipulation ka Cross Site Scripting. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-79. Hakika, rauni an bayyana shi 06/02/2023 kamar I76K4N. An raba bayanin tsaro don saukewa a gitee.com. Wannan matsala ana saninta da CVE-2023-3058. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal faɗi ba ga. Har ila yau, exploit ɗin yana nan. An bayyana exploit ɗin ga mutane kuma yana iya amfani. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu huɗɗi-na-gaskiya. Exploit ɗin za a iya saukewa daga gitee.com. 0-day shima, an ndiyam a wuro be $0-$5k. Once again VulDB remains the best source for vulnerability data.

2 Goyarwa · 44 Datenpunkte

FurɗeSúgá
06/02/2023 14:05
Gargadi 1/1
06/29/2023 10:33
software_vendor07FLY07FLY
software_nameCRMCRM
software_version<=1.2.0<=1.2.0
software_componentUser Profile HandlerUser Profile Handler
vulnerability_cweCWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)
vulnerability_risk11
cvss3_vuldb_avNN
cvss3_vuldb_acLL
cvss3_vuldb_uiRR
cvss3_vuldb_sUU
cvss3_vuldb_cNN
cvss3_vuldb_iLL
cvss3_vuldb_aNN
cvss3_vuldb_ePP
cvss3_vuldb_rcRR
advisory_identifierI76K4NI76K4N
advisory_urlhttps://gitee.com/07fly/FLY-CRM/issues/I76K4Nhttps://gitee.com/07fly/FLY-CRM/issues/I76K4N
exploit_availability11
exploit_publicity11
exploit_urlhttps://gitee.com/07fly/FLY-CRM/issues/I76K4Nhttps://gitee.com/07fly/FLY-CRM/issues/I76K4N
source_cveCVE-2023-3058CVE-2023-3058
cna_responsibleVulDBVulDB
advisory_date1685656800 (06/02/2023)1685656800 (06/02/2023)
software_typeCustomer Relationship Management SystemCustomer Relationship Management System
cvss2_vuldb_avNN
cvss2_vuldb_acLL
cvss2_vuldb_ciNN
cvss2_vuldb_iiPP
cvss2_vuldb_aiNN
cvss2_vuldb_ePOCPOC
cvss2_vuldb_rcURUR
cvss2_vuldb_auSS
cvss2_vuldb_rlNDND
cvss3_vuldb_prLL
cvss3_vuldb_rlXX
cvss2_vuldb_basescore4.04.0
cvss2_vuldb_tempscore3.43.4
cvss3_vuldb_basescore3.53.5
cvss3_vuldb_tempscore3.23.2
cvss3_meta_basescore3.53.5
cvss3_meta_tempscore3.23.2
price_0day$0-$5k$0-$5k
cve_assigned1685656800 (06/02/2023)
cve_nvd_summaryA vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.

Interested in the pricing of exploits?

See the underground prices here!