vendor:
mooDating
by:
CraCkEr aka (skalvin)
6.1
CVSS
MEDIUM
Reflected Cross-site scripting (XSS)
79
CWE
Product Name: mooDating
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: CVE-2023-3849, CVE-2023-3848, CVE-2023-3847, CVE-2023-3846, CVE-2023-3843, CVE-2023-3845, CVE-2023-3844
CPE: a:moosocial:moodating:1.2
Platforms Tested: Windows 10 Pro
2023
mooDating 1.2 – Reflected Cross-site scripting (XSS)
The attacker can send to victim a link containing a malicious URL in an email or instant message can perform a wide variety of actions, such as stealing the victim's session token or login credentials
Mitigation:
Implement input validation and output encoding to prevent the execution of malicious scripts.