An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repox | Third Party Advisory |
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repox | Third Party Advisory |
Configurations
History
21 Nov 2024, 08:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repox - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
18 Dec 2023, 17:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repox - Third Party Advisory | |
CPE | cpe:2.3:a:europeana:repox:2.3.7:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
First Time |
Europeana
Europeana repox |
13 Dec 2023, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-13 10:15
Updated : 2024-11-21 08:44
NVD link : CVE-2023-6720
Mitre link : CVE-2023-6720
CVE.ORG link : CVE-2023-6720
JSON object : View
Products Affected
europeana
- repox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')