Description
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
Published: 2023-10-29
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54257 HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
History

Wed, 25 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Sep 2024 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-116
CWE-147

Subscriptions

Liquidfiles Liquidfiles
cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2024-09-25T11:55:18.386Z

Reserved: 2023-08-17T01:02:50.748Z

Link: CVE-2023-4393

cve-icon Vulnrichment

Updated: 2024-08-02T07:24:04.605Z

cve-icon NVD

Status : Modified

Published: 2023-10-30T00:15:39.237

Modified: 2024-11-21T08:35:03.273

Link: CVE-2023-4393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.