Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source and onerror attributes to execute arbitrary JavaScript code in victim's browser.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zomp
Zomp zomplog |
|
| CPEs | cpe:2.3:a:zomp:zomplog:3.9:*:*:*:*:*:*:* | |
| Vendors & Products |
Zomp
Zomp zomplog |
|
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zomplog
Zomplog zomplog |
|
| Vendors & Products |
Zomplog
Zomplog zomplog |
Tue, 16 Dec 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source and onerror attributes to execute arbitrary JavaScript code in victim's browser. | |
| Title | Zomplog 3.9 Cross-Site Scripting Vulnerability via Page Creation | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:22.198Z
Updated: 2025-12-15T21:46:43.279Z
Reserved: 2025-12-13T14:25:05.001Z
Link: CVE-2023-53887
Updated: 2025-12-15T21:37:51.732Z
Status : Analyzed
Published: 2025-12-15T21:15:51.833
Modified: 2025-12-24T18:13:07.030
Link: CVE-2023-53887
No data.