CVE-2023-25295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/01/2024
Last modified:
17/06/2025

Description

A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gruen:evewa3:*:*:*:*:*:*:*:* 31 (including) 53 (including)