CVE-2023-4492: Easy Address Book Web Server Project Easy Address Book Web Server
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the application is loaded
Affected products
- Easy Address Book Web Server Project Easy Address Book Web Server: version 1.6 only
Published 2023-10-04. Last modified 2026-06-17.