CVE Published: 20/12/2023 |
CVE Updated: 21/11/2024 |
CVE Year: 2023 Source: INCIBE |
Vendor: Amazing Little poll |
Product: Amazing Little poll Status : PUBLISHED
CVE-2023-6769 Description
Stored XSS vulnerability in Amazing Little Poll, affecting versions 1.3 and 1.4. This vulnerability allows a remote attacker to store a malicious JavaScript payload in the "lp_admin.php" file in the "question" and "item" parameters. This vulnerability could lead to malicious JavaScript execution while the page is loading.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N