CVE-2023-32607: Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote...

0.0 CVSS

Description

Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.

Classification

CVE ID: CVE-2023-32607

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Implem Inc.

Product: Pleasanter (Community Edition and Enterprise Edition)

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.07% (probability of being exploited)

EPSS Percentile: 34.55% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://pleasanter.org/archives/vulnerability-update-202306
https://jvn.jp/en/jp/JVN97818024/

Timeline