PT-2023-19091 · Express+1 · Express+1

Nebrelbug

·

Publicado

2023-01-31

·

Atualizado

2023-02-08

·

CVE-2023-23630

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Eta versions prior to 2.0.0
Description The issue is related to a XSS attack that impacts anyone using the Express API. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include passing user-supplied data directly to the res.render function.
Recommendations For versions prior to 2.0.0, upgrade to version 2.0.0 to resolve the issue. As a temporary workaround, do not pass user-supplied things directly to res.render or res.renderFile.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-23630
GHSA-XRH7-M5PP-39R6

Produtos afetados

Eta
Express