CVE-2023-33181: Medium severity Xibosignage Xibo vulnerability
Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xibo content management system (CMS)to a version that resolves this vulnerability.Fixed in 3.3.5
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33181?
CVE-2023-33181 is considered to have a medium severity due to the potential exposure of sensitive information.
How do I fix CVE-2023-33181?
To fix CVE-2023-33181, users should upgrade to Xibo version 3.3.5 or later.
Which versions of Xibo are affected by CVE-2023-33181?
CVE-2023-33181 affects Xibo version 3.0.0 up to, but not including, version 3.3.5.
What types of information can be leaked due to CVE-2023-33181?
CVE-2023-33181 can leak sensitive information about server paths through error stack traces.
Is there a patch for CVE-2023-33181?
Yes, the patch for CVE-2023-33181 is included in Xibo version 3.3.5 and later.