Solidres 2.13.3 and earlier contain a reflected cross-site scripting flaw reachable without authentication through several GET parameters, including show, reviews, type_id, distance, facilities, categories, prices, location and Itemid. A crafted link executes JavaScript in the visitor browser and can be used to steal session tokens. CVSS 6.1 (Medium). Update to a current Solidres release (3.x or 4.x).
Is my site affected?
Affected
Solidres up to and including 2.13.3
Fixed in
A release after 2.13.3
What to do
Update Solidres to the newest release from the vendor. This flaw covers versions up to 2.13.3, so any later release is outside it.
The base metrics as VulnCheck CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
CVE-2023-54363 affects Solidres up to and including 2.13.3.
How do I fix CVE-2023-54363?
Update Solidres to the newest release from the vendor. This flaw covers versions up to 2.13.3, so any later release is outside it.
How severe is CVE-2023-54363?
VulnCheck CNA scores it 5.1 (Medium) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and someone has to be talked through a few steps.
Running an affected version on a site you manage?
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
We use essential cookies to run the site. With your consent we also use Google Analytics and a Meta pixel to measure and improve our marketing. See our cookie policy.