PatchSiren cyber security CVE debrief
CVE-2023-7153 Macroturk Software and Internet Technologies CVE debrief
A reflected cross-site scripting (XSS) vulnerability exists in Macro-Bel, a software product developed by Macroturk Software and Internet Technologies. The flaw stems from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that execute in the context of a victim's browser session. This vulnerability affects all versions of Macro-Bel prior to V.1.0.1. The issue was disclosed publicly on January 18, 2024, with the CVE record subsequently modified on May 20, 2026. The vulnerability carries a CVSS 3.1 score of 6.1 (Medium severity), reflecting network attack vector, low attack complexity, no required privileges, and required user interaction. The scope is changed, with low impacts to confidentiality and integrity. Turkish cybersecurity authorities have issued security advisories regarding this vulnerability.
- Vendor
- Macroturk Software and Internet Technologies
- Product
- Macro-Bel
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-01-18
- Original CVE updated
- 2026-05-20
- Advisory published
- 2024-01-18
- Advisory updated
- 2026-05-20
Who should care
Organizations running Macro-Bel web applications, particularly those serving authenticated users or processing sensitive data. Security teams in Turkish government and enterprise sectors should prioritize given national authority involvement. Web application developers and security engineers responsible for input validation and output encoding in similar PHP or web-based enterprise applications.
Technical summary
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). It is a reflected XSS issue, meaning malicious payloads are typically delivered through crafted URLs or form submissions and execute immediately in the victim's browser without persistent storage. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N indicates network accessibility, low attack complexity, no privilege requirements, required user interaction, changed scope, and low impacts to confidentiality and integrity with no availability impact. The fix version V.1.0.1 indicates proper input sanitization was implemented in that release.
Defensive priority
medium
Recommended defensive actions
- Upgrade Macro-Bel to version 1.0.1 or later to remediate the reflected XSS vulnerability
- Implement Content Security Policy (CSP) headers to mitigate impact of any residual XSS vectors
- Review and sanitize all user-supplied input in web page generation contexts
- Deploy web application firewall (WAF) rules to detect and block common XSS payloads
- Monitor for exploitation attempts via application logs and security information and event management (SIEM) systems
Evidence notes
Vulnerability confirmed through official CVE publication and Turkish national cybersecurity authority (USOM) advisories. CPE criteria confirm affected versions are all releases before 1.0.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-7153 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-7153
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-7153 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-7153
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-0041
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-24-0041
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.