{"id":"GHSA-432f-967f-vxg4","summary":"Evolution CMS Cross-site Scripting vulnerability","details":"Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters","aliases":["CVE-2023-43340"],"modified":"2026-09-10T03:49:24.657201583Z","published":"2023-10-20T00:30:25Z","database_specific":{"nvd_published_at":"2023-10-19T23:15:08Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-10-20T22:32:53Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43340"},{"type":"PACKAGE","url":"https://github.com/evolution-cms/evolution"},{"type":"WEB","url":"https://github.com/sromanhu/-CVE-2023-43340-Evolution-Reflected-XSS---Installation-Admin-Options"},{"type":"WEB","url":"https://github.com/sromanhu/Evolution-Reflected-XSS---Installation-Admin-Options"}],"affected":[{"package":{"name":"evolutioncms/evolution","ecosystem":"Packagist","purl":"pkg:composer/evolutioncms/evolution"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.2.3"}]}],"versions":["1.4.10","1.4.11","1.4.12","1.4.13","1.4.14","1.4.15","1.4.16","1.4.17","1.4.18","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","2.0","2.0.0-RC","2.0.0-alpha","2.0.1","2.0.2","2.0.3","2.0.4","3.0","3.0.1","3.0.2","3.0RC","3.0RC2","3.0RC3","3.1.0","3.1.1","3.1.10","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","3.2.0","3.2.1","3.2.2","3.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-432f-967f-vxg4/GHSA-432f-967f-vxg4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}