{"api_version":"1","generated_at":"2026-07-24T20:58:50+00:00","cve":"CVE-2023-3784","urls":{"html":"https://cve.report/CVE-2023-3784","api":"https://cve.report/api/cve/CVE-2023-3784.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-3784","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-3784"},"summary":{"title":"CVE-2023-3784","description":"A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-07-20 09:15:00","updated_at":"2023-11-07 04:19:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://vuldb.com/?id.235051","name":"https://vuldb.com/?id.235051","refsource":"MISC","tags":[],"title":"CVE-2023-3784: Dooblou WiFi File Explorer cross site scripting","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.235051","name":"https://vuldb.com/?ctiid.235051","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://seclists.org/fulldisclosure/2023/Jul/37","name":"https://seclists.org/fulldisclosure/2023/Jul/37","refsource":"MISC","tags":[],"title":"Full Disclosure: Dooblou WiFi File Explorer 1.13.3 - Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.vulnerability-lab.com/get_content.php?id=2317","name":"https://www.vulnerability-lab.com/get_content.php?id=2317","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-3784","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3784","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"3784","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wifi_file_explorer_project","cpe5":"wifi_file_explorer","cpe6":"1.13.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-3784","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051."},{"lang":"deu","value":"In Dooblou WiFi File Explorer 1.13.3 wurde eine problematische Schwachstelle ausgemacht. Das betrifft eine unbekannte Funktionalität. Durch die Manipulation des Arguments search/order/download/mode mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross Site Scripting","cweId":"CWE-79"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Dooblou","product":{"product_data":[{"product_name":"WiFi File Explorer","version":{"version_data":[{"version_affected":"=","version_value":"1.13.3"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.235051","refsource":"MISC","name":"https://vuldb.com/?id.235051"},{"url":"https://vuldb.com/?ctiid.235051","refsource":"MISC","name":"https://vuldb.com/?ctiid.235051"},{"url":"https://www.vulnerability-lab.com/get_content.php?id=2317","refsource":"MISC","name":"https://www.vulnerability-lab.com/get_content.php?id=2317"},{"url":"https://seclists.org/fulldisclosure/2023/Jul/37","refsource":"MISC","name":"https://seclists.org/fulldisclosure/2023/Jul/37"}]},"impact":{"cvss":[{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"},{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"},{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}]}},"nvd":{"publishedDate":"2023-07-20 09:15:00","lastModifiedDate":"2023-11-07 04:19:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wifi_file_explorer_project:wifi_file_explorer:1.13.3:*:*:*:*:android:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}