Vulnerability Details CVE-2023-29998
A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 36.0%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2023-29998
-
cpe:2.3:a:gis3w:g3w-suite:3.5