First published: Tue Apr 04 2023(Updated: )
Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uptime Kuma | <=1.19.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26777 is classified as a high-severity Cross Site Scripting vulnerability.
To mitigate CVE-2023-26777, upgrade Uptime Kuma to version 1.19.7 or later.
CVE-2023-26777 can allow remote attackers to execute arbitrary scripts in a user's browser.
CVE-2023-26777 affects Uptime Kuma version 1.19.6 and earlier.
CVE-2023-26777 can be exploited through the description, title, footer, and incident creation parameters of the status_page.js endpoint.