CVE-2023-3973: Cross-site Scripting (XSS) - Reflected in jgraph/drawio
Published Jul 27, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3.
Affected Software
1 affected component
Diagrams Drawio<21.6.3
Remediation
Event History
Jul 27, 2023
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-3973?
CVE-2023-3973 is a vulnerability categorized as Cross-site Scripting (XSS) - Reflected in the GitHub repository jgraph/drawio prior to version 21.6.3.
2
How severe is CVE-2023-3973?
CVE-2023-3973 has a severity rating of critical with a score of 6.1.
3
Which software is affected by CVE-2023-3973?
The vulnerability affects the Drawio software with versions up to and excluding 21.6.3.
4
How can I fix CVE-2023-3973?
To fix CVE-2023-3973, you should update your Drawio software to version 21.6.3 or higher.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-3973?
The CWE ID for CVE-2023-3973 is 79.