Headline
CVE-2023-43267: CVE-2023-43267
A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.
[CVE ID]
CVE-2023-43267
[PRODUCT]
emlog - pro
[VERSION]
2.1.14
[PROBLEM TYPE]
Cross Site Scripting (XSS)
[DESCRIPTION]
Emlog pro has a storage based XSS vulnerability in its article publishing function, which can be used to steal information such as cookies from others