PT-2023-30449 · Pachno · Pachno

Herombey

·

Published

2023-11-27

·

Updated

2023-12-01

·

CVE-2023-47437

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pachno version 1.0.6
Description A vulnerability has been identified that allows an authenticated attacker to execute a cross-site scripting (XSS) attack. The issue exists due to inadequate input validation in the Project Description and comments, enabling an attacker to inject malicious JavaScript.
Recommendations For Pachno version 1.0.6, consider implementing proper input validation for the Project Description and comments to prevent malicious JavaScript injection. As a temporary workaround, restrict the ability to input JavaScript code in these fields until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-47437

Affected Products

Pachno