A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-02T08:28:21.824Z

Reserved: 2023-11-30T10:02:15.643Z

Link: CVE-2023-6419

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-30T14:15:19.333

Modified: 2024-11-21T08:43:49.167

Link: CVE-2023-6419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.