Medium severity5.4NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-43191
CVE-2023-43191
Description
SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comments, these malicious codes embedded in the HTML will be executed, and the user's browser will be controlled by the attacker, so as to achieve the special purpose of the attacker, such as cookie theft
Affected products
3- cpe:2.3:a:jrecms:springbootcms:1.0:*:*:*:*:*:*:*
- SpringbootCMS/SpringbootCMSdescription
- Range: <=1.0
Patches
Vulnerability mechanics
References
1- github.com/etn0tw/cmscve_test/blob/main/README.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.