CVE-2023-0736: Cross-site Scripting (XSS) - Stored in wallabag/wallabag
Published Feb 7, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.
Affected Software
1 affected component
wallabag wallabag<2.5.4
Remediation
Event History
Feb 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-0736?
CVE-2023-0736 is a vulnerability that allows for Cross-site Scripting (XSS) attacks in the GitHub repository wallabag/wallabag prior to version 2.5.4.
2
How does CVE-2023-0736 affect wallabag?
CVE-2023-0736 affects wallabag versions up to and excluding 2.5.4, allowing for the possibility of Cross-site Scripting (XSS) attacks.
3
What is the severity of CVE-2023-0736?
The severity of CVE-2023-0736 is medium with a severity value of 5.4.
4
How can I fix CVE-2023-0736?
To fix CVE-2023-0736, you should update your wallabag installation to version 2.5.4 or later.
5
Where can I find more information about CVE-2023-0736?
You can find more information about CVE-2023-0736 on the GitHub page of wallabag/wallabag and the Huntr.dev bounty page.