Vulnerability Description
Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the application is loaded
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easy Address Book Web Server Project | Easy Address Book Web Server | 1.6 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-efs-Third Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-efs-Third Party Advisory
FAQ
What is CVE-2023-4492?
CVE-2023-4492 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) o...
How severe is CVE-2023-4492?
CVE-2023-4492 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4492?
Check the references section above for vendor advisories and patch information. Affected products include: Easy Address Book Web Server Project Easy Address Book Web Server.