CVE-2023-37988
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-37988 is a reflected Cross-Site Scripting (XSS) vulnerability affecting the Creative Solutions Contact Form Generator plugin versions 2.5.5 and below. Attackers can inject malicious scripts into a website using this vulnerability, which can then be executed in users' browsers when they view a specially crafted webpage. The attacker gains no direct access to the targeted system but can steal sensitive information, perform actions on behalf of the user, or redirect the user to malicious websites. Users are strongly advised to update the plugin to a secure version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Creative Solutions, Inc.