1 results (0.027 seconds)
CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 2
CVE-2023-25440 – CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)
https://notcve.org/view.php?id=CVE-2023-25440
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field. CiviCRM version 5.59.alpha1 suffers from a persistent cross site scripting vulnerability. • https://www.exploit-db.com/exploits/51478 https://civicrm.org https://packetstormsecurity.com/files/172470/CiviCRM-5.59.alpha1-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •