CVE-2023-54341
EUVD-2026-259213.01.2026, 23:16
Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| webgrind_project | webgrind | 𝑥 ≤ 1.1 |
𝑥
= Vulnerable software versions