PT-2023-16427 · Yafnet · Yafnet

Chun-Li Lin

+1

·

Published

2023-02-02

·

Updated

2024-05-17

·

CVE-2023-0650

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions YAFNET versions up to 3.1.11
Description A vulnerability was found in the Signature Handler component of YAFNET, which can lead to cross-site scripting. The attack may be initiated remotely. The issue affects some unknown processing of this component.
Recommendations For YAFNET versions up to 3.1.11, upgrade to version 3.1.12 to address this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-0650
GHSA-MG6P-JJFF-7G5M

Affected Products

Yafnet