Stored XSS vulnerability in Usememos Memos could lead to sensitive information theft
CVE-2023-0109
5.4MEDIUM
Key Information:
- Vendor
- Usememos
- Status
- Usememos/memos
- Vendor
- CVE Published:
- 15 November 2024
Summary
A stored cross-site scripting (XSS) vulnerability exists in Usememos Memos version 0.9.1, enabling attackers to upload a JavaScript file with a malicious script. By referencing this script in an HTML document, an attacker can execute the script when users access the compromised file. The exploitation of this vulnerability can lead to unauthorized access to sensitive user data, including login credentials, exposing users to significant security risks. The issue has been addressed and resolved in version 0.10.0, highlighting the importance of upgrading to the latest version to ensure protection against such attacks.
Affected Version(s)
usememos/memos < 0.10.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved