PT-2023-16156 · Alf.Io · Alf.Io

Published

2023-01-14

·

Updated

2023-01-24

·

CVE-2023-0301

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Alf.io versions prior to 2.0-M4-2301
Description The issue is related to Cross-site Scripting (XSS) - Stored, which was found in the GitHub repository alfio-event/alf.io. This type of issue allows an attacker to inject malicious scripts into a website, potentially leading to unauthorized access or control.
Recommendations For versions prior to 2.0-M4-2301, update to Alf.io version 2.0-M4-2301 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-0301

Affected Products

Alf.Io