PT-2024-11919 · Unknown · Usememos/Memos

Published

2024-11-15

·

Updated

2024-11-20

·

CVE-2023-0109

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions usememos/memos version 0.9.1
Description A stored cross-site scripting (XSS) vulnerability was discovered, allowing an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed, potentially leading to the theft of sensitive information, such as login credentials, from users visiting the affected website.
Recommendations For usememos/memos version 0.9.1, update to version 0.10.0 to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-0109
GHSA-5R2G-59PX-3Q9W
GO-2024-3274
OPENSUSE-SU-2024:14513-1

Affected Products

Usememos/Memos