S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-3846 Scanner

CVE-2023-3846 scanner - Cross-Site Scripting (XSS) vulnerability in mooSocial mooDating

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-3846
6.1
CVSSlow
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

A vulnerability classified as problematic has been found in mooSocial mooDating 1.2. This affects an unknown part of the file /pages of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235197 was assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
mooDatingby mooSocial
1.2
Updated Aug 22, 2026View on NVD →
Detail

MooSocial's mooDating 1.2 is an online dating platform designed for individuals and organizations to create interactive, user-friendly dating communities. This software is widely utilized for its ability to facilitate connections, relationships, and networking among users. By incorporating social networking features with dating services, mooDating offers a comprehensive tool for enhancing social interaction online. The platform is particularly popular among website developers and entrepreneurs who wish to offer a unique social and dating experience on their websites.

The Cross-Site Scripting (XSS) vulnerability identified in CVE-2023-3846 within mooSocial's mooDating 1.2 platform allows attackers to inject malicious scripts into web pages. This issue arises due to inadequate validation of user input in the URL handler component associated with the /pages file. When exploited, this vulnerability can enable attackers to execute arbitrary code in the context of the victim's browser, leading to potential data theft, session hijacking, and other malicious activities.

Specifically, the XSS vulnerability exists in the handling of input through the /pages endpoint of mooDating 1.2, where malicious scripts can be embedded in URL parameters. These scripts are inadvertently executed by the browser when users navigate to the crafted URL. The lack of proper input sanitation in this component allows attackers to construct URLs that trigger the vulnerability, exploiting the platform's trust in user input to execute unintended actions or reveal sensitive information.

The exploitation of this XSS vulnerability can have severe consequences for users and the platform alike. Users may become victims of identity theft, unauthorized access to personal data, and manipulation of their accounts. For the platform, this represents a significant security risk, potentially undermining user trust, damaging the platform's reputation, and possibly leading to financial and legal repercussions.

Joining the S4E platform enables users to benefit from cutting-edge vulnerability detection and cyber threat exposure management services. Our tools and expertise provide an essential layer of security, identifying and mitigating vulnerabilities like CVE-2023-3846 in mooSocial's mooDating. Membership offers access to comprehensive scans, expert analysis, and actionable recommendations, helping to secure digital assets, protect user data, and maintain trust and reliability in the face of evolving cyber threats.

 

References

Solution Advice
  1. Update mooSocial's mooDating software to the latest version that addresses this XSS vulnerability.
  2. Implement robust input validation and sanitization measures to prevent malicious code injection through user inputs.
  3. Adopt a secure coding practice that includes regular security reviews and vulnerability testing of the software.
  4. Educate users on the risks of clicking on unknown links and the importance of maintaining secure browsing practices.
  5. Regularly monitor and audit the platform for new vulnerabilities, ensuring timely detection and remediation of potential security issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.