Stored XSS vulnerability in Usememos Memos could lead to sensitive information theft
CVE-2023-0109
5.4MEDIUM
What is CVE-2023-0109?
A stored cross-site scripting (XSS) vulnerability exists in Usememos Memos version 0.9.1, enabling attackers to upload a JavaScript file with a malicious script. By referencing this script in an HTML document, an attacker can execute the script when users access the compromised file. The exploitation of this vulnerability can lead to unauthorized access to sensitive user data, including login credentials, exposing users to significant security risks. The issue has been addressed and resolved in version 0.10.0, highlighting the importance of upgrading to the latest version to ensure protection against such attacks.
Affected Version(s)
usememos/memos < 0.10.0