PT-2023-30449 · Pachno · Pachno
Herombey
·
Publicado
2023-11-27
·
Atualizado
2023-12-01
·
CVE-2023-47437
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pachno version 1.0.6
Description
A vulnerability has been identified that allows an authenticated attacker to execute a cross-site scripting (XSS) attack. The issue exists due to inadequate input validation in the Project Description and comments, enabling an attacker to inject malicious JavaScript.
Recommendations
For Pachno version 1.0.6, consider implementing proper input validation for the Project Description and comments to prevent malicious JavaScript injection. As a temporary workaround, restrict the ability to input JavaScript code in these fields until a patch is available.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pachno