Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-44812

EPSS 49.70% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-44812

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
mooSocial 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
mooSocial是mooSocial公司的一个多平台、移动就绪、用户友好的脚本。用于构建社区驱动的内容共享和社交网络网站。 mooSocial v.3.1.8版本存在安全漏洞。攻击者利用该漏洞通过特制的有效载荷对user login函数的admin_redirect_url参数执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2023-44812

#POC DescriptionSource LinkShenlong Link
1mooSocial v3.1.8 is vulnerable to cross-site scripting on Admin redirect function.https://github.com/ahrixia/CVE-2023-44812POC Details
2A cross-site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code by sending a crafted payload to the admin_redirect_url parameter of the user login function. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-44812.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-44812

登录查看更多情报信息。

Same Patch Batch · n/a · 2023-10-09 · 26 CVEs total

CVE-2023-45371MediaWiki 安全漏洞
CVE-2023-43899HANSUNCMS SQL注入漏洞
CVE-2023-44467LangChain 安全漏洞
CVE-2023-44811MooSocial 跨站请求伪造漏洞
CVE-2023-44821gifsicle 安全漏洞
CVE-2022-36228Nokelock 安全漏洞
CVE-2023-4327170mai a500s 访问控制错误漏洞
CVE-2023-44813mooSocial 跨站脚本漏洞
CVE-2023-45363MediaWiki 安全漏洞
CVE-2023-45364MediaWiki 安全漏洞
CVE-2023-45367MediaWiki 安全漏洞
CVE-2023-45369MediaWiki 安全漏洞
CVE-2023-45370MediaWiki 安全漏洞
CVE-2023-45356Atos Unify OpenScape 命令注入漏洞
CVE-2023-45372MediaWiki 安全漏洞
CVE-2023-45373MediaWiki 跨站脚本漏洞
CVE-2023-45374MediaWiki 安全漏洞
CVE-2023-39854ATX Ucrypt 代码问题漏洞
CVE-2023-45349Atos Unify OpenScape 安全漏洞
CVE-2023-45350Atos Unify OpenScape 安全漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-44812

No comments yet


Leave a comment