← back
CVE-2023-2399medium

qubotchat < 1.1.6 - Unauthenticated Stored XSS

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · QuBot