CVE-2023-0549 is a cross-site scripting (XSS) vulnerability affecting YAFNET versions up to 3.1.10, specifically within the Private Message Handler component when processing the /forum/PostPrivateMessage file. An authenticated attacker can exploit this remotely by manipulating the subject or message arguments. Rated with a CVSS score of 5.4 (Medium), this vulnerability has a low attack complexity and requires user interaction, potentially leading to limited impact on confidentiality and integrity. While public exploit details are available, there is no evidence of active exploitation in the wild, nor are there Metasploit or Nuclei modules. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, <= 3.1.10CPE matchmatch criteria | cpe:2.3:a:yetanotherforum:yaf.net:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.