Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search.
References
Link | Resource |
---|---|
https://srpopty.github.io/2023/02/15/Vulnerability-Discuz-X3.4-Reflected-XSS-(CVE-2022-45543)/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2023-02-15 13:15
Updated : 2023-02-22 20:58
NVD link : CVE-2022-45543
Mitre link : CVE-2022-45543
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
discuz
- discuzx