CVE-2023-1496: Cross-site Scripting (XSS) - Reflected in imgproxy/imgproxy
Published Mar 19, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
Affected Software
1 affected component
Evilmartians Imgproxy<3.14.0
Remediation
Event History
Mar 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1496?
CVE-2023-1496 has been classified as a moderate severity vulnerability due to its potential for exploitation through reflected cross-site scripting.
2
How do I fix CVE-2023-1496?
To fix CVE-2023-1496, update imgproxy to version 3.14.0 or later.
3
Who is affected by CVE-2023-1496?
CVE-2023-1496 affects users of imgproxy prior to version 3.14.0.
4
What type of vulnerability is CVE-2023-1496?
CVE-2023-1496 is classified as a Cross-site Scripting (XSS) vulnerability.
5
How can CVE-2023-1496 be exploited?
CVE-2023-1496 can be exploited by injecting malicious scripts into user inputs that are reflected back on the page.