cve/2023/CVE-2023-4492.md
2024-05-25 21:48:12 +02:00

942 B

CVE-2023-4492

Description

Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the application is loaded

POC

Reference

No PoCs from references.

Github