CVE-2023-44812 is a Cross-Site Scripting (XSS) vulnerability in mooSocial v.3.1.8, allowing remote attackers to execute arbitrary code through a crafted payload in the admin_redirect_url parameter of the user login function. Rated 6.1 MEDIUM on CVSS, it requires user interaction (UI:R) but can be exploited over the network (AV:N) with low attack complexity (AC:L), potentially leading to limited confidentiality and integrity impacts (C:L, I:L). While there are Nuclei templates available for detection, there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.8CPE matchmatch criteria | cpe:2.3:a:moosocial:moosocial:3.1.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.