Skip to content

ADD CVE-2023-2437.yaml (vKEV)#13448

Merged
DhiyaneshGeek merged 11 commits intoprojectdiscovery:mainfrom
intelligent-ears:ADD-CVE-2023-2437
Oct 31, 2025
Merged

ADD CVE-2023-2437.yaml (vKEV)#13448
DhiyaneshGeek merged 11 commits intoprojectdiscovery:mainfrom
intelligent-ears:ADD-CVE-2023-2437

Conversation

@intelligent-ears
Copy link
Copy Markdown
Contributor

Template / PR Information

Template Validation

I've validated this template locally?

  • YES
  • NO
┌──(intel_ears㉿kali)-[~/…/nuclei-templates/http/cves/2023]
└─$ nuclei -t CVE-2023-2437.yaml -u http://localhost:8080 -debug

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.4.6

		projectdiscovery.io

[WRN] Found 1 templates loaded with deprecated protocol syntax, update before v3 for continued support.
[INF] Current nuclei version: v3.4.6 (outdated)
[INF] Current nuclei-templates version: v10.2.9 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 182
[INF] Templates loaded for current scan: 1
[WRN] Loading 1 unsigned templates for scan. Use with caution.
[INF] Targets loaded for current scan: 1
[INF] [CVE-2023-2437] Dumped HTTP request for http://localhost:8080/wp-content/plugins/userpro/css/userpro.min.css

GET /wp-content/plugins/userpro/css/userpro.min.css HTTP/1.1
Host: localhost:8080
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

[DBG] [CVE-2023-2437] Dumped HTTP response http://localhost:8080/wp-content/plugins/userpro/css/userpro.min.css

HTTP/1.1 200 OK
Connection: close
Accept-Ranges: bytes
Content-Type: text/css
Date: Wed, 01 Oct 2025 12:09:34 GMT
Etag: "b1d7-63e0b58f0c380-gzip"
Last-Modified: Fri, 05 Sep 2025 10:31:58 GMT
Server: Apache/2.4.51 (Debian)
Vary: Accept-Encoding

.userpro-sc .userpro-profile-badge.userpro-profile-badge-online.userpro-hide-from-list{display:none !important}.userpro-sc-action-remove.userpro-tip{box-shadow:none;bottom:15%;position:absolute;right:2%}.userpro_connection_accepted{margin- .
.
.
.
.
holder{width:100%;height:500px}a:hover{box-shadow:none !important;text-decoration:none}a{box-shadow:none;text-decoration:none}#bbpress-forums .userpro-badges{margin:0 !important}.bbpress-usepro-div{display:inline-block}div.userpro-overlay-inner div.userpro a.userpro-close-popup {margin-top: 50px;z-index: 300;display: block!important;color: black!important;}
[CVE-2023-2437:word-1] [http] [critical] http://localhost:8080/wp-content/plugins/userpro/css/userpro.min.css
[CVE-2023-2437:status-2] [http] [critical] http://localhost:8080/wp-content/plugins/userpro/css/userpro.min.css
[INF] Scan completed in 16.355244ms. 2 matches found.

Additional Details (leave it blank if not applicable)

Additional References:

@github-actions github-actions Bot requested a review from DhiyaneshGeek October 1, 2025 12:19
@intelligent-ears intelligent-ears changed the title ADD CVE-2023-2473.yaml (vKEV) ADD CVE-2023-2437.yaml (vKEV) Oct 2, 2025
@pussycat0x pussycat0x added the Status: On Hold Similar to blocked, but is assigned to someone label Oct 2, 2025
@ritikchaddha ritikchaddha added Done Ready to merge and removed Status: On Hold Similar to blocked, but is assigned to someone labels Oct 30, 2025
ritikchaddha and others added 2 commits October 30, 2025 15:42
Added additional references and updated matchers and extractors for CVE-2023-2437.
@DhiyaneshGeek DhiyaneshGeek merged commit c0bfbee into projectdiscovery:main Oct 31, 2025
3 checks passed
@intelligent-ears intelligent-ears deleted the ADD-CVE-2023-2437 branch October 31, 2025 07:09
@algora-pbc
Copy link
Copy Markdown

algora-pbc Bot commented Nov 5, 2025

🎉🎈 @intelligent-ears has been awarded $200 by ProjectDiscovery! 🎈🎊

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants