{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-6472","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-12-02T03:01:51.529Z","datePublished":"2023-12-02T18:31:03.772Z","dateUpdated":"2024-08-02T08:28:21.802Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-12-02T18:31:03.772Z"},"title":"PHPEMS Content Section api.cls.php cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Cross Site Scripting"}]}],"affected":[{"vendor":"n/a","product":"PHPEMS","versions":[{"version":"7.0","status":"affected"}],"modules":["Content Section Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, has been found in PHPEMS 7.0. This issue affects some unknown processing of the file app\\content\\cls\\api.cls.php of the component Content Section Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246629 was assigned to this vulnerability."},{"lang":"de","value":"Eine Schwachstelle wurde in PHPEMS 7.0 entdeckt. Sie wurde als problematisch eingestuft. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Datei app\\content\\cls\\api.cls.php der Komponente Content Section Handler. Durch das Beeinflussen mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":2.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":2.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":3.3,"vectorString":"AV:N/AC:L/Au:M/C:N/I:P/A:N"}}],"timeline":[{"time":"2023-12-02T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-12-02T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-12-02T04:11:34.000Z","lang":"en","value":"VulDB entry last update"}],"references":[{"url":"https://vuldb.com/?id.246629","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.246629","tags":["signature","permissions-required"]},{"url":"https://www.yuque.com/u39339523/el4dxs/vs8kw5gql9646xx4","tags":["exploit"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T08:28:21.802Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.246629","tags":["vdb-entry","x_transferred"]},{"url":"https://vuldb.com/?ctiid.246629","tags":["signature","permissions-required","x_transferred"]},{"url":"https://www.yuque.com/u39339523/el4dxs/vs8kw5gql9646xx4","tags":["exploit","x_transferred"]}]}]}}