CVE-2023-7259

2.4 LOW
Published: May 24, 2024 Modified: April 15, 2026
View on NVD

Description

** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-266127. NOTE: The vendor rejected the issue because he claims that XSS which require administrative privileges are not of any use for attackers.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://vuldb.com/?ctiid.266127
Source: cna@vuldb.com
https://vuldb.com/?id.266127
Source: cna@vuldb.com
https://gitee.com/zzdevelop/lenosp/issues/I7XC2Y
Source: af854a3a-2127-422b-91ae-364da2661108
https://vuldb.com/?ctiid.266127
Source: af854a3a-2127-422b-91ae-364da2661108
https://vuldb.com/?id.266127
Source: af854a3a-2127-422b-91ae-364da2661108

6 reference(s) from NVD

Quick Stats

CVSS v3 Score
2.4 / 10.0
EPSS (Exploit Probability)
0.1%
27th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)