Critical XSS Vulnerability in CiviCRM and PostfixAdmin Affecting Multiple Ubuntu Releases

Critical XSS Vulnerability in CiviCRM and PostfixAdmin Affecting Multiple Ubuntu Releases

First seen 8 May 2026, 04:41 UTC Linuxsecurity 73% similarity 70.5

Article Content

Browse articles
ThreatCluster

A critical cross-site scripting (XSS) vulnerability, CVE-2023-28447, affects CiviCRM and PostfixAdmin across several Ubuntu versions, including 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, and 24.04 LTS. Discovered by Takuya Aramaki, the flaw allows attackers to execute malicious JavaScript in users' browsers through specially crafted input. The vulnerability was first published on March 28, 2023, with a proof of concept available shortly after. Ubuntu has released updates to mitigate this issue, and users are advised to update their systems promptly. The problem is particularly concerning due to its potential for exploitation in environments using these applications. The advisory emphasizes the importance of applying the updates to prevent possible attacks.

Key Points: • CVE-2023-28447 affects CiviCRM and PostfixAdmin across multiple Ubuntu versions. • Attackers can exploit the vulnerability to execute malicious JavaScript in users' browsers. • Users are urged to update their systems immediately to mitigate the risk.

ThreatCluster AI

Timeline

2023-03-28
CVE-2023-28447 published
A cross-site scripting vulnerability in CiviCRM was disclosed, affecting multiple Ubuntu versions.
Linuxsecurity
2023-03-30
First public PoC for CVE-2023-28447
A proof of concept for exploiting the XSS vulnerability was made available to the public.
Linuxsecurity
2026-05-07
Ubuntu releases patches for CiviCRM and PostfixAdmin
Ubuntu issued updates to fix the XSS vulnerability in CiviCRM and PostfixAdmin, urging users to apply them.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story