Cross Site Scripting Vulnerability in EverShop NPM by Checkmarx
CVE-2023-46499

6.1MEDIUM

Key Information:

Vendor

Evershop

Status
Vendor
CVE Published:
8 December 2023

What is CVE-2023-46499?

A Cross Site Scripting vulnerability exists in EverShop NPM versions prior to v.1.0.0-rc.5. This flaw allows remote attackers to execute crafted scripts within the Admin Panel, potentially leading to unauthorized access to sensitive information. Utilizing this vulnerability, an attacker could inject malicious scripts that would be executed in the context of an unsuspecting administrator's session, compromising the integrity and confidentiality of application data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.