Cross-site Scripting (XSS) - Stored in usememos/memos
CVE-2023-0108

7.1HIGH

Key Information:

Vendor
Usememos
Vendor
CVE Published:
7 January 2023

Summary

A stored Cross-Site Scripting (XSS) vulnerability has been identified in Memos, a note-taking application maintained by usememos. This vulnerability affects all versions prior to 0.10.0, allowing attackers to inject malicious scripts into the application. When unsuspecting users interact with the compromised content, the malicious script executes in their web browsers, potentially leading to unauthorized actions and data exposure. It is crucial for users of Memos to upgrade to version 0.10.0 or later to mitigate this risk and ensure the security of their data.

Affected Version(s)

usememos/memos < 0.10.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

CVSS V3.0

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.