Medium severity6.1NVD Advisory· Published Oct 4, 2023· Updated Jun 17, 2026
CVE-2023-27121
CVE-2023-27121
Description
A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:pleasantsolutions:pleasant_password_server:7.11.41:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pleasantsolutions:pleasant_password_server:7.11.41:*:*:*:*:*:*:*
- (no CPE)range: = 7.11.41.0
- Pleasant Solutions/Pleasant Password Serverdescription
Patches
Vulnerability mechanics
References
3- www.mdsec.co.uk/2023/09/the-not-so-pleasant-password-manager/nvdExploitThird Party Advisory
- pleasantpasswords.com/downloadnvdProduct
- www.nuget.org/packages/CronExpressionDescriptor/2.9.0nvdNot Applicable
News mentions
0No linked articles in our index yet.