Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-30212

EPSS 75.16% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-30212

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OURPHP 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OURPHP是OURPHP开源的一个开源、跨平台、企业级+电商+小程序+APP多终端同步的CMS建站系统。 OURPHP 7.2.0版本及之前版本存在安全漏洞,该漏洞源于通过文件ourphp_out.php发现包含跨站脚本(XSS)漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2023-30212

#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/kuttappu123/CVE-2023-30212-LABPOC Details
2This repository provides a Docker container for simulating the CVE-2023-30212 vulnerability, allowing you to practice and understand its impact. It includes a comprehensive guide to help you set up the container on your own computer. The documentation for the Docker creation process is also included.https://github.com/Rishipatidar/CVE-2023-30212-POC-DOCKER-FILEPOC Details
3GitHub repository with Dockerfile and files to create a vulnerable environment for CVE-2023-30212, enabling exploration of the exploitability of this security vulnerability. Ideal for research and security enthusiasts to study and understand the impact of the vulnerability in a controlled setting.https://github.com/mallutrojan/CVE-2023-30212-LabPOC Details
4Nonehttps://github.com/Anandhu990/CVE-2023-30212_labPOC Details
5Docker environment and exploit the CVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or equal to 7.2.0 .This vulnerability allows for Cross-Site Scripting (XSS) attackshttps://github.com/libas7994/CVE-2023-30212POC Details
6Docker environment and exploit the CVE-2023-30212 vulnerability that affects versions of OURPHP prior to or equal to 7.2.0. This vulnerability allows for Cross-Site Scripting (XSS) attackshttps://github.com/libasmon/Vulnerable-Docker-Environment-CVE-2023-30212POC Details
7Docker environment and exploit the CVE-2023-30212 vulnerabilityVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or equal to 7.2.0. This vulnerability allows for Cross-Site Scripting (XSS) attackshttps://github.com/libasmon/-create-a-vulnerable-Docker-environment-that-is-susceptible-to-CVE-2023-30212POC Details
8Docker environment and exploit the CVE-2023-30212 vulnerabilityVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or equal to 7.2.0. This vulnerability allows for Cross-Site Scripting (XSS) attackshttps://github.com/libasmon/Exploite-CVE-2023-30212-VulnerabilityPOC Details
9Vulnerable Docker Environment CVE-2023-30212https://github.com/libas7994/Exploit-the-CVE-2023-30212-vulnerabilityPOC Details
10Exploit-the-CVE-2023-30212-vulnerabilityhttps://github.com/libasv/Exploite-CVE-2023-30212-vulnerabilityPOC Details
11Nonehttps://github.com/kai-iszz/CVE-2023-30212POC Details
12Nonehttps://github.com/MaThEw-ViNcEnT/CVE-2023-30212-OURPHP-VulnerabilityPOC Details
13Nonehttps://github.com/arunsnap/CVE-2023-30212-POCPOC Details
14Nonehttps://github.com/VisDev23/Vulnerable-Docker-CVE-2023-30212POC Details
15This contains the necessary files and Docker to replicate A vulnerability in OURPHP that has a XSS Vulnerability (CVE-2023-30212)https://github.com/VisDev23/Vulnerable-Docker--CVE-2023-30212-POC Details
16Nonehttps://github.com/AAsh035/CVE-2023-30212POC Details
17Nonehttps://github.com/JasaluRah/Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212-POC Details
18OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-30212.yamlPOC Details
19PoC for CVE-2023-30212 using Dockerhttps://github.com/sungmin20/cve-2023-30212POC Details
20Nonehttps://github.com/imathewvincent/CVE-2023-30212-OURPHP-VulnerabilityPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-30212

登录查看更多情报信息。

Same Patch Batch · n/a · 2023-04-26 · 26 CVEs total

CVE-2023-22943.5 LOWUCMS Column Configuration saddpost.php cross site scripting
CVE-2022-44232libming 安全漏洞
CVE-2023-24796Vinga WR-AC1200 安全漏洞
CVE-2022-39989Fighting Cock Information System 信任管理问题漏洞
CVE-2023-30112Medicine Tracker System SQL注入漏洞
CVE-2023-30265CLTPHP 路径遍历漏洞
CVE-2023-30266CLTPHP 代码问题漏洞
CVE-2023-30267CLTPHP 跨站脚本漏洞
CVE-2023-30269CLTPHP 输入验证错误漏洞
CVE-2022-27978ToolJet 安全漏洞
CVE-2022-27979ToolJet 跨站脚本漏洞
CVE-2023-30210OURPHP 跨站脚本漏洞
CVE-2023-30211OURPHP SQL注入漏洞
CVE-2023-27107MyQ Solution Print Server和MyQ Solution Central Server 安全漏洞
CVE-2023-26930Glyph & Cog XpdfReader 安全漏洞
CVE-2020-36070Voyager 安全漏洞
CVE-2023-26567FreePBX 安全漏洞
CVE-2023-29596Cmix 安全漏洞
CVE-2023-29835Wondershare Dr.Fone 安全漏洞
CVE-2023-29836Exelysis Unified Communication Solutions 跨站脚本漏洞

Showing top 20 of 26 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-30212

No comments yet


Leave a comment