A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the "/pmcadmin/configure.php" parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-11-30T13:38:43.344Z

Updated: 2024-08-02T08:21:17.157Z

Reserved: 2023-11-08T09:59:43.079Z

Link: CVE-2023-6027

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-30T14:15:14.497

Modified: 2023-12-06T02:26:53.783

Link: CVE-2023-6027

cve-icon Redhat

No data.