MEDIUM🇵🇱 Wersja polska

CVE-2023-35859

CVSS 6.1v3.1pub. 2024-06-13upd. 2025-03-17

A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts or HTML via multiple parameters.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Moderncampus Omni Cms

    APP
    Moderncampus
    2023.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2022-40766CRITICAL9.8PL ✓same product

SQL Injection na stronie logowania w Modern Campus Omni CMS

CVE-2023-35858MEDIUM5.3same product

XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remot...

CVE-2023-35860MEDIUM5.3same product

A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attack...