Cross-site Scripting Vulnerability in OrangeScrum Application
CVE-2023-0738
6.1MEDIUM
What is CVE-2023-0738?
An application flaw in OrangeScrum version 2.0.11 allows external attackers to exploit the system by leveraging improper input handling. By manipulating user input, attackers can extract arbitrary user accounts as the application returns the input directly in the HTTP response with the content-type incorrectly set to text/html. This can lead to unauthorized access and exposure of sensitive user information, emphasizing the criticality of addressing such vulnerabilities in web applications.
Affected Version(s)
OrangeScrum 2.0.11
