A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the "/pmcadmin/configure.php" parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-11-30T13:38:43.344Z
Updated: 2024-08-02T08:21:17.157Z
Reserved: 2023-11-08T09:59:43.079Z
Link: CVE-2023-6027
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2023-11-30T14:15:14.497
Modified: 2023-12-06T02:26:53.783
Link: CVE-2023-6027
Redhat
No data.