Stored Cross-Site Scripting Vulnerability in SHIRASAGI by SS Proj
CVE-2023-38569

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 September 2023

What is CVE-2023-38569?

A stored cross-site scripting vulnerability exists in SHIRASAGI prior to version 1.18.0. This flaw enables remote authenticated attackers to inject arbitrary scripts that could be executed in the web browsers of users during their login sessions. The exploitation of this vulnerability could allow attackers to steal sensitive information or manipulate the behavior of the web application, compromising user security and trust.

Affected Version(s)

SHIRASAGI prior to v1.18.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.