CVE-2023-32671

Publication date

2023-10-03 12:26:44

Family

INCIBE

State

PUBLISHED

Description

A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.