PatchSiren cyber security CVE debrief
CVE-2023-3652 Digital Ant CVE debrief
CVE-2023-3652 is a reflected cross-site scripting (XSS) issue in Digital Ant E-Commerce Software affecting versions before 11. The NVD record classifies it as CWE-79 and rates it CVSS 6.1 (medium). Because the vector includes user interaction and scope change, the practical risk is strongest where attackers can lure users into loading crafted web content in an affected application flow.
- Vendor
- Digital Ant
- Product
- E-Commerce Software
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-08-08
- Original CVE updated
- 2026-05-21
- Advisory published
- 2023-08-08
- Advisory updated
- 2026-05-21
Who should care
Organizations running Digital Ant E-Commerce Software versions earlier than 11, especially internet-facing deployments or teams responsible for web application security, customer portals, or authenticated admin interfaces.
Technical summary
The vulnerability is an improper neutralization of input during web page generation, resulting in reflected XSS. NVD lists the affected CPE as digital-ant:digital_ant with versions before 11 (versionEndExcluding 11). The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) indicates network reachability, no privileges required, user interaction required, and limited confidentiality/integrity impact with scope change.
Defensive priority
Medium priority: patch affected instances to version 11 or later, then verify exposed application paths that render user-controlled input.
Recommended defensive actions
- Upgrade Digital Ant E-Commerce Software to version 11 or later, consistent with the NVD affected-version boundary.
- Review all user-supplied input that is rendered into HTML responses and ensure output encoding is applied in the affected pages or components.
- Validate any vendor or national CSIRT guidance referenced by NVD/USOM for this CVE before and after remediation.
- If the application is internet-facing, prioritize testing and rollback planning so the upgrade can be deployed quickly and safely.
- Monitor for unexpected script execution reports, unusual browser-side behavior, or web logs that suggest reflected payload attempts against the affected component.
Evidence notes
This debrief is based on the supplied NVD record for CVE-2023-3652 and its cited references. The record states the weakness as CWE-79, the vulnerability status as Modified, and the affected version range as before 11. NVD also includes USOM references (tr-23-0443) as source material. No KEV entry or ransomware-campaign linkage is present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-3652 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-3652
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-3652 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-3652
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0443
-
Source reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0443
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://https//www.usom.gov.tr/bildirim/tr-23-0443
af854a3a-2127-422b-91ae-364da2661108 - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.