CVE-2023-4492: Easy Address Book Web Server Project Easy Address Book Web Server

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the application is loaded

Affected products

Published 2023-10-04. Last modified 2026-06-17.