CVE-2023-0106: Cross-site Scripting (XSS) - Stored in usememos/memos
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-0106?
CVE-2023-0106 is a vulnerability related to Cross-site Scripting (XSS) in the GitHub repository usememos/memos prior to version 0.10.0.
How does CVE-2023-0106 affect users?
CVE-2023-0106 allows attackers to inject malicious scripts into web pages viewed by users of the affected GitHub repository usememos/memos prior to version 0.10.0, potentially leading to unauthorized actions or data theft.
What is the severity of CVE-2023-0106?
The severity of CVE-2023-0106 is rated as critical, with a severity value of 5.4.
How can I fix CVE-2023-0106?
To fix CVE-2023-0106, users should update their usememos/memos GitHub repository to version 0.10.0 or later, which includes the necessary security patches.
Where can I find more information about CVE-2023-0106?
More information about CVE-2023-0106 can be found at the following references: [GitHub commit](https://github.com/usememos/memos/commit/0f8ce3dd1696722f951d7195ad1f88b39a5d15d7) and [Huntr Bounty](https://huntr.dev/bounties/5c0809cb-f4ff-4447-bed6-b5625fb374bb).