Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information. | |
| Title | Jorani 1.0.3 Cross-Site Scripting Vulnerability via Language Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:14.132Z
Updated: 2025-12-15T21:48:23.741Z
Reserved: 2025-12-13T14:25:04.998Z
Link: CVE-2023-53870
Updated: 2025-12-15T21:41:33.128Z
Status : Received
Published: 2025-12-15T21:15:49.403
Modified: 2025-12-15T21:15:49.403
Link: CVE-2023-53870
No data.