A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-10-03T12:26:44.072Z

Updated: 2023-10-03T12:26:44.072Z

Reserved: 2023-05-11T08:48:57.515Z


Link: CVE-2023-32671

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-03T13:15:10.220

Modified: 2023-10-11T18:10:04.837


Link: CVE-2023-32671

JSON object: View

cve-icon Redhat Information

No data.

CWE