CVE-2023-30962: Stored XSS in cerberus attachments
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30962?
CVE-2023-30962 is a stored cross-site scripting (XSS) vulnerability found in the Gotham Cerberus service.
What is the severity of CVE-2023-30962?
CVE-2023-30962 has a severity rating of 5.4, which is considered medium.
How does CVE-2023-30962 affect the Gotham Cerberus service?
CVE-2023-30962 allows an attacker with access to Gotham to launch cross-site scripting attacks against other users of the service.
How can I fix CVE-2023-30962?
To fix CVE-2023-30962, update the Gotham Cerberus service to version 100.230704.0-27-g031dd58 or later.
What is the Common Weakness Enumeration (CWE) identifier for CVE-2023-30962?
CVE-2023-30962 is classified under CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.