CVE-2023-5313

A vulnerability classified as problematic was found in phpkobo Ajax Poll Script 3.18. Affected by this vulnerability is an unknown functionality of the file ajax-poll.php of the component Poll Handler. The manipulation leads to improper enforcement of a single, unique action. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240949 was assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpkobo:ajax_poll_script:3.18:*:*:*:*:*:*:*

History

21 Nov 2024, 08:41

Type Values Removed Values Added
References () https://github.com/tht1997/WhiteBox/blob/main/PHPKOBO/ajax_pool_script.md - Exploit () https://github.com/tht1997/WhiteBox/blob/main/PHPKOBO/ajax_pool_script.md - Exploit
References () https://vuldb.com/?ctiid.240949 - Permissions Required () https://vuldb.com/?ctiid.240949 - Permissions Required
References () https://vuldb.com/?id.240949 - Permissions Required () https://vuldb.com/?id.240949 - Permissions Required
CVSS v2 : 5.0
v3 : 3.7
v2 : 5.0
v3 : 5.3

03 Oct 2023, 20:05

Type Values Removed Values Added
References (MISC) https://github.com/tht1997/WhiteBox/blob/main/PHPKOBO/ajax_pool_script.md - (MISC) https://github.com/tht1997/WhiteBox/blob/main/PHPKOBO/ajax_pool_script.md - Exploit
References (MISC) https://vuldb.com/?id.240949 - (MISC) https://vuldb.com/?id.240949 - Permissions Required
References (MISC) https://vuldb.com/?ctiid.240949 - (MISC) https://vuldb.com/?ctiid.240949 - Permissions Required
First Time Phpkobo ajax Poll Script
Phpkobo
CPE cpe:2.3:a:phpkobo:ajax_poll_script:3.18:*:*:*:*:*:*:*
CWE CWE-837 CWE-362
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7

30 Sep 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-30 15:15

Updated : 2024-11-21 08:41


NVD link : CVE-2023-5313

Mitre link : CVE-2023-5313

CVE.ORG link : CVE-2023-5313


JSON object : View

Products Affected

phpkobo

  • ajax_poll_script
CWE
CWE-837

Improper Enforcement of a Single, Unique Action

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')