ZeroHour

CVE-2023-31506

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p61
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.

Vendors
getgrav
Products
grav
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.