Cross-Site Scripting Vulnerability in Memos Server by Use Memos
CVE-2022-25978
6.1MEDIUM
Summary
The Memos Server, developed by Use Memos, is exposed to Cross-Site Scripting (XSS) vulnerabilities across all versions due to inadequate validation of external resources. This flaw could allow attackers to inject malicious scripts by leveraging links that utilize the 'javascript:' scheme. Such vulnerabilities can lead to serious security breaches, enabling unauthorized actions on behalf of unsuspecting users. Immediate action is necessary to secure applications against potential exploitation.
Affected Version(s)
github.com/usememos/memos/server 0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kahla