First published: Sat Jan 07 2023(Updated: )
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Usememos Memos | <0.10.0 | |
<0.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0106 is a vulnerability related to Cross-site Scripting (XSS) in the GitHub repository usememos/memos prior to version 0.10.0.
CVE-2023-0106 allows attackers to inject malicious scripts into web pages viewed by users of the affected GitHub repository usememos/memos prior to version 0.10.0, potentially leading to unauthorized actions or data theft.
The severity of CVE-2023-0106 is rated as critical, with a severity value of 5.4.
To fix CVE-2023-0106, users should update their usememos/memos GitHub repository to version 0.10.0 or later, which includes the necessary security patches.
More information about CVE-2023-0106 can be found at the following references: [GitHub commit](https://github.com/usememos/memos/commit/0f8ce3dd1696722f951d7195ad1f88b39a5d15d7) and [Huntr Bounty](https://huntr.dev/bounties/5c0809cb-f4ff-4447-bed6-b5625fb374bb).