{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2023-30212/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ourphp:ourphp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2023-30212"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ourphp (\u003c= 7.2.0)"],"_cs_severities":["low"],"_cs_tags":["web-application","xss","cve-2023-30212"],"_cs_type":"advisory","_cs_vendors":["Ourphp"],"content_html":"\u003cp\u003eOurphp versions 7.2.0 and earlier contain a reflected cross-site scripting (XSS) vulnerability, identified as CVE-2023-30212. The vulnerability resides in the '/client/manage/ourphp_out.php' file, where the 'out' parameter is insufficiently sanitized when the 'ourphp_admin' parameter is set to 'logout'. An attacker can craft a malicious URL containing arbitrary JavaScript payloads, which will then be executed within the context of a victim's browser if they navigate to the link. This flaw, classified with a CVSS 6.1 score, poses a risk of session hijacking, credential theft, and unauthorized actions performed on behalf of the victim. Public proof-of-concept (PoC) code has been released, increasing the risk of exploitation for organizations still running affected versions of the software.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target running Ourphp version 7.2.0 or earlier.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious URL pointing to the vulnerable endpoint: '/client/manage/ourphp_out.php?ourphp_admin=logout\u0026amp;out=[PAYLOAD]'.\u003c/li\u003e\n\u003cli\u003eAttacker injects a JavaScript payload into the 'out' parameter (e.g., '\u0026lt;script\u0026gt;alert(1)\u0026lt;/script\u0026gt;').\u003c/li\u003e\n\u003cli\u003eAttacker uses social engineering or phishing to trick an authenticated or targeted user into clicking the malicious link.\u003c/li\u003e\n\u003cli\u003eThe victim's browser requests the endpoint with the injected script.\u003c/li\u003e\n\u003cli\u003eThe Ourphp application reflects the unsanitized payload back to the victim's browser.\u003c/li\u003e\n\u003cli\u003eThe browser executes the injected script in the context of the user's active session, enabling token theft or forced actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-30212 enables an attacker to execute arbitrary scripts in the victim's browser session. This can lead to the compromise of user sessions, theft of sensitive information (such as session cookies or CSRF tokens), and the potential to perform unauthorized administrative actions if the victim is an authorized user. The vulnerability is network-accessible and requires user interaction, making it a viable target for credential-harvesting or session-hijacking campaigns.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize upgrading all instances of Ourphp to a version beyond 7.2.0, as there is currently no evidence of an official patch release for this specific legacy version mentioned in the source material.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for exploitation attempts targeting the identified endpoint in web server logs.\u003c/li\u003e\n\u003cli\u003eImplement Content Security Policy (CSP) headers to mitigate the impact of reflected XSS by restricting where scripts can be loaded and executed.\u003c/li\u003e\n\u003cli\u003eEducate users on the risks of clicking suspicious links, especially those directing to internal administrative portals.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T10:28:02Z","date_published":"2026-09-18T10:28:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ourphp-xss/","summary":"Ourphp versions 7.2.0 and earlier are vulnerable to reflected cross-site scripting (XSS) via the 'out' parameter in the 'ourphp_out.php' endpoint, allowing unauthorized script execution in a victim's browser session.","title":"Reflected XSS in Ourphp via ourphp_out.php","url":"https://feed.craftedsignal.io/briefs/2026-09-ourphp-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2023-30212","version":"https://jsonfeed.org/version/1.1"}