CVE-2023-1799

Source
https://cve.org/CVERecord?id=CVE-2023-1799
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1799.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-1799
Published
2023-04-02T10:00:06.308Z
Modified
2026-07-15T01:49:11.468077716Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
EyouCMS login.php cross site scripting
Details

A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of the file login.php. The manipulation of the argument tag_tag leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224751.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1799.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.5.0"
                },
                {
                    "last_affected": "1.5.0"
                },
                {
                    "introduced": "1.5.1"
                },
                {
                    "last_affected": "1.5.1"
                },
                {
                    "introduced": "1.5.2"
                },
                {
                    "last_affected": "1.5.2"
                },
                {
                    "introduced": "1.5.3"
                },
                {
                    "last_affected": "1.5.3"
                },
                {
                    "introduced": "1.5.4"
                },
                {
                    "last_affected": "1.5.4"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/weng-xianhu/eyoucms

Affected ranges

Type
GIT
Repo
https://github.com/weng-xianhu/eyoucms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "cpe": "cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.5.4"
        }
    ]
}

Affected versions

v1.*
v1.5.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1799.json"