PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/51415 | Exploit Third Party Advisory VDB Entry |
| https://www.phpjabbers.com/ | Product |
| https://www.vulncheck.com/advisories/phpjabbers-simple-cms-stored-cross-site-scripting-via-section-creation | Exploit Third Party Advisory |
| https://www.exploit-db.com/exploits/51415 | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2025-12-17 23:15
Updated : 2025-12-27 17:15
NVD link : CVE-2023-53927
Mitre link : CVE-2023-53927
CVE.ORG link : CVE-2023-53927
JSON object : View
Products Affected
phpjabbers
- simple_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
