RULE(RULE ID:337789)

Rule General Information
Release Date: 2024-01-16
Rule Name: Typecho 1.2.0 Cross-site Scripting Vulnerability (CVE-2023-27711)
Severity:
CVE ID:
Rule Protection Details
Description: Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://github.com/typecho/typecho/issues/1539
https://srpopty.github.io/2023/03/02/Typecho-V1.2.0-Backend-Reflected-XSS-cid/
https://cxsecurity.com/cveshow/CVE-2023-27711/
Solutions
Refer to the announcement or patch by the vendor: https://github.com/penndu/typecho/commit/665320f7e09eeb241ca482ac41cec59f8cb90d18