Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jorani
Jorani jorani |
|
| Vendors & Products |
Jorani
Jorani jorani |
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information. | |
| Title | Jorani 1.0.3 Cross-Site Scripting Vulnerability via Language Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:14.132Z
Updated: 2025-12-15T21:48:23.741Z
Reserved: 2025-12-13T14:25:04.998Z
Link: CVE-2023-53870
Updated: 2025-12-15T21:41:33.128Z
Status : Awaiting Analysis
Published: 2025-12-15T21:15:49.403
Modified: 2025-12-16T14:10:11.300
Link: CVE-2023-53870
No data.