Stored XSS vulnerability in Usememos Memos could lead to sensitive information theft
CVE-2023-0109

5.4MEDIUM

Key Information:

Vendor
Usememos
Status
Usememos/memos
Vendor
CVE Published:
15 November 2024

Summary

A stored cross-site scripting (XSS) vulnerability exists in Usememos Memos version 0.9.1, enabling attackers to upload a JavaScript file with a malicious script. By referencing this script in an HTML document, an attacker can execute the script when users access the compromised file. The exploitation of this vulnerability can lead to unauthorized access to sensitive user data, including login credentials, exposing users to significant security risks. The issue has been addressed and resolved in version 0.10.0, highlighting the importance of upgrading to the latest version to ensure protection against such attacks.

Affected Version(s)

usememos/memos < 0.10.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.