CVE-2023-6439

Source
https://cve.org/CVERecord?id=CVE-2023-6439
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6439.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-6439
Published
2023-11-30T19:31:04.133Z
Modified
2026-07-15T01:48:49.921098752Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
ZenTao PMS cross site scripting
Details

A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246439.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6439.json",
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "18.8"
                },
                {
                    "last_affected": "18.8"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/easysoft/zentaopms

Affected ranges

Type
GIT
Repo
https://github.com/easysoft/zentaopms
Events
Database specific
{
    "cpe": "cpe:2.3:a:easycorp:zentao:18.8:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "18.8"
        },
        {
            "last_affected": "18.8"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

18.*
18.8
zentaopms_18.*
zentaopms_18.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6439.json"