CVE-2023-24769: XSS
Changedetection.io before 0.40.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
Other sources
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24769?
CVE-2023-24769 is characterized as a stored cross-site scripting (XSS) vulnerability, which poses a significant security risk.
How do I fix CVE-2023-24769?
To mitigate CVE-2023-24769, upgrade Changedetection.io to version 0.40.2 or higher.
What type of attacks can CVE-2023-24769 enable?
CVE-2023-24769 allows attackers to execute arbitrary web scripts or HTML, potentially compromising user data and website integrity.
Which versions of Changedetection.io are vulnerable to CVE-2023-24769?
Changedetection.io versions prior to 0.40.2, including 0.40.1.1, are vulnerable to CVE-2023-24769.
What is the impact of exploiting CVE-2023-24769?
Exploiting CVE-2023-24769 can lead to session hijacking, phishing attacks, and unauthorized access to sensitive information.