VulnerabilityModified
CVE-2023-5378
Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions up to 4.36.2.
MEDIUM 5.4EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions up to 4.36.2. MegaBIP 5.08 was tested and is not vulnerable. A precise range of vulnerable versions remains unknown.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- megabip/megabip · smod/smodbip
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2023/12/CVE-2023-5378Third Party Advisory
- https://cert.pl/posts/2023/12/CVE-2023-5378Third Party Advisory
- https://megabip.pl/Product
- https://smod.pl/Product
- https://cert.pl/en/posts/2023/12/CVE-2023-5378Third Party Advisory
- https://cert.pl/posts/2023/12/CVE-2023-5378Third Party Advisory
- https://megabip.pl/Product
- https://smod.pl/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.