CVE-2023-23011: XSS
Published Feb 7, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filterproduct input to file modalproductlookups.php.
Affected Software
5 affected components
InvoicePlane InvoicePlane=1.6.0
InvoicePlane InvoicePlane=1.6.0-beta
InvoicePlane InvoicePlane=1.6.0-beta1
InvoicePlane InvoicePlane=1.6.0-beta2
InvoicePlane InvoicePlane=1.6.0-beta3
Event History
Feb 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-23011?
CVE-2023-23011 is a Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via the filter_product input to file modal_product_lookups.php.
2
What software versions are affected by CVE-2023-23011?
InvoicePlane versions 1.6.0, 1.6.0-beta, 1.6.0-beta1, 1.6.0-beta2, and 1.6.0-beta3 are affected by CVE-2023-23011.
3
What is the severity of CVE-2023-23011?
CVE-2023-23011 has a severity rating of medium with a CVSS score of 6.1.
4
How can I fix CVE-2023-23011?
To fix CVE-2023-23011, it is recommended to update InvoicePlane to a version that includes a patch for the vulnerability.
5
Where can I find more information about CVE-2023-23011?
More information about CVE-2023-23011 can be found in the following references: [link1], [link2].