SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4393

HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.

MEDIUM 6.1EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.31% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-116, CWE-147, CWE-74, CWE-79
Affected
liquidfiles/liquidfiles
Source
vdp@themissinglink.com.au

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.