CVE-2023-32670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/10/2023
Last modified:
04/10/2023

Description

Cross-Site Scripting vulnerability <br /> <br /> in BuddyBoss 2.2.9 version<br /> <br /> , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:buddyboss:buddyboss:2.2.9:*:*:*:*:wordpress:*:*