cbcvebase.
CVE-2023-27293
published 2023-02-28

CVE-2023-27293: Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire…

PriorityP344medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
56.77%
99.0th percentile
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

Affected

1 ranges
VendorProductVersion rangeFixed in
opencatsopencats
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.