CVE-2023-28733
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when acce…
MEDIUM
acymailing
Description
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
Sévérité
6.1
Moyenne · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.1 (v3.1) |
Produit et versions
- Produit
- acymailing
- Corrigée dans
- 8.3.0
- Publiée
- 30/03/2023
- Modifiée
- 17/06/2026
- CWE
- CWE-116, CWE-20, CWE-79
Versions concernées
- Newsletter Plugin for Joomla in the Enterprise version — 0 – 0
- acymailing — jusqu'à 8.3.0 (exclue)
Sources
- NVD CVE-2023-28733 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC