First published: Mon Jul 03 2023(Updated: )
2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested in docker-compose environment. This vulnerability has been patched in version 4.0.3.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE YaST | <4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36816 has a severity rating that can vary based on the context of exposure, but it is recognized as a significant cross-site scripting (XSS) vulnerability.
To fix CVE-2023-36816, update to version 4.0.3 or later of the 2FAuth application.
CVE-2023-36816 is a Cross-Site Scripting (XSS) injection vulnerability affecting the service/account field in the 2FAuth web application.
CVE-2023-36816 is present in all versions of 2FAuth prior to version 4.0.3.
There is no specific workaround; the recommended action is to upgrade to the patched version 4.0.3.