Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form.
References
Link | Resource |
---|---|
https://github.com/boxbilling/boxbilling/issues/596 | Exploit Issue Tracking |
https://github.com/boxbilling/boxbilling/issues/596 | Exploit Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/boxbilling/boxbilling/issues/596 - Exploit, Issue Tracking |
Information
Published : 2023-04-28 20:15
Updated : 2024-11-21 05:13
NVD link : CVE-2020-23647
Mitre link : CVE-2020-23647
CVE.ORG link : CVE-2020-23647
JSON object : View
Products Affected
boxbilling
- boxbilling
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')