Vulnerability Description
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acymailing | Acymailing | < 8.3.0 |
Related Weaknesses (CWE)
References
- https://www.acymailing.com/change-log/Release Notes
- https://www.bugbounty.ch/advisories/CVE-2023-28733Third Party Advisory
- https://www.acymailing.com/change-log/Release Notes
- https://www.bugbounty.ch/advisories/CVE-2023-28733Third Party Advisory
FAQ
What is CVE-2023-28733?
CVE-2023-28733 is a vulnerability with a CVSS score of 7.2 (HIGH). AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation ...
How severe is CVE-2023-28733?
CVE-2023-28733 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28733?
Check the references section above for vendor advisories and patch information. Affected products include: Acymailing Acymailing.