CVE-2023-47240
Medium
|6.5Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker with contributor-level access to inject malicious scripts into the CBX Map plugin, which can then execute in the browsers of users who view the affected maps. This means that if an attacker can get contributor access, they can potentially steal sensitive information or perform actions on behalf of other users.
Technical Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Codeboxr CBX Map for Google Map & OpenStreetMap plugin <= 1.1.11 versions.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactLow
ScopeChanged
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:LExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$931($500-$1K)
Vendor Response
Grade FPatched in 820 days
Quick Information
Published
Nov 16, 2023
over 2 years ago
Last Modified
Feb 13, 2026
7 days ago
Vendor
codeboxr
Product
cbx map