CVE-2023-48824 describes multiple stored Cross-Site Scripting (XSS) vulnerabilities in BoidCMS version 2.0.1, specifically exploitable through the title, subtitle, footer, or keywords parameters during a page creation action. This medium-severity vulnerability (CVSS 5.4) requires low privileges and user interaction, allowing an attacker to inject malicious scripts that could lead to limited impact on confidentiality and integrity. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the underlying weakness is CWE-79 (Improper Neutralization of Input During Web Page Generation).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.1CPE matchmatch criteria | cpe:2.3:a:boidcms:boidcms:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.