CVE-2023-5024
Published on: Not Yet Published
Last Modified on: 09/20/2023 03:45:00 PM UTC
Certain versions of Planning Biblio from Planno contain the following vulnerability:
A vulnerability was found in Planno 23.04.04. It has been classified as problematic. This affects an unknown part of the component Comment Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239865 was assigned to this vulnerability.
- CVE-2023-5024 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 4.8 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE-2023-5024: Planno Comment cross site scripting | vuldb.com text/html |
![]() |
Page d’accueil - Planno | www.planno.fr text/html |
![]() |
Authenticated Reflected XSS in planno version 23.04.04 - YouTube | youtu.be text/html |
![]() |
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Planno | Planning Biblio | 23.04.04 | All | All | All |
- cpe:2.3:a:planno:planning_biblio:23.04.04:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE