Stored XSS Vulnerability in JetBrains YouTrack Markdown Rendering Engine
CVE-2023-35054
5.4MEDIUM
What is CVE-2023-35054?
In JetBrains YouTrack versions before 2023.1.10518, a security vulnerability was identified in the Markdown-rendering engine that allows for stored Cross-Site Scripting (XSS). By exploiting this flaw, attackers can potentially inject malicious scripts into content that is stored and rendered in the application, leading to unauthorized actions or data exposure when users interact with the affected content.
Affected Version(s)
YouTrack 0 < 2023.1.10518
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved