A reflected cross-site scripting (XSS) vulnerability exisits in the q parameter on search function of mooSocial v3.1.8 which allows attackers to steal user's session cookies and impersonate their account via a crafted URL.
id: CVE-2023-45542
info:
name: MooSocial 3.1.8 - Cross-Site Scripting
author: r3Y3r53
severit
...