{ "id": "CVE-2023-38911", "sourceIdentifier": "cve@mitre.org", "published": "2023-08-18T19:15:13.113", "lastModified": "2023-08-18T20:11:33.760", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields." } ], "metrics": {}, "references": [ { "url": "https://github.com/desencrypt/CVE/blob/main/CVE-2023-1/Readme.md", "source": "cve@mitre.org" }, { "url": "https://github.com/desencrypt/CVE/tree/main/CVE-2023-1", "source": "cve@mitre.org" } ] }