CVE-2023-47240

Medium
|6.5
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker with contributor-level access to inject malicious scripts into the CBX Map plugin, which can then execute in the browsers of users who view the affected maps. This means that if an attacker can get contributor access, they can potentially steal sensitive information or perform actions on behalf of other users.

Technical Description

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Codeboxr CBX Map for Google Map & OpenStreetMap plugin <= 1.1.11 versions.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactLow
ScopeChanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$931($500-$1K)
Vendor Response
Grade FPatched in 820 days

Quick Information

Published

Nov 16, 2023

over 2 years ago

Last Modified

Feb 13, 2026

7 days ago

Vendor

codeboxr

Product

cbx map