Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ev3Rr3D

#47246de 53,633
5.4CVSS total
Vulnerabilidades · 1
PT-2023-31568
5.4
2023-12-10
Monica · Monica · CVE-2023-50465
**Name of the Vulnerable Software and Affected Versions** Monica (aka MonicaHQ) version 4.0.0 **Description** A stored cross-site scripting (XSS) vulnerability exists in the software via an SVG document uploaded by an authenticated user. **Recommendations** For version 4.0.0, consider restricting the upload of SVG documents by authenticated users until a patch is available. As a temporary workaround, disabling the feature to upload SVG files can help minimize the risk of exploitation.