Medium severity6.1OSV Advisory· Published Jan 13, 2026· Updated Jun 17, 2026
CVE-2023-54341
CVE-2023-54341
Description
Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:webgrind_project:webgrind:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:webgrind_project:webgrind:*:*:*:*:*:*:*:*range: <=1.1
- (no CPE)range: <=1.1
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/51074nvdExploit
- www.vulncheck.com/advisories/webgrind-reflected-cross-site-scripting-xss-via-file-parameternvdThird Party Advisory
News mentions
0No linked articles in our index yet.