CVE-2023-45998: XSS
Published Oct 23, 2023
·Updated
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
Affected Software
1 affected component
Kodcloud Kodbox=1.44
Event History
Oct 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45998?
The severity of CVE-2023-45998 is medium with a CVSS score of 5.4.
2
How does kodbox 1.44 become vulnerable to Cross Site Scripting (XSS)?
Customizing global HTML in kodbox 1.44 results in storing XSS, making it vulnerable to Cross Site Scripting (XSS).
3
What software versions are affected by CVE-2023-45998?
kodbox version 1.44 is affected by CVE-2023-45998.
4
Is there a fix for CVE-2023-45998?
At the moment, no fix is available for CVE-2023-45998. It is recommended to stay updated with the latest security patches and follow best security practices to minimize the risk.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-45998?
The CWE ID associated with CVE-2023-45998 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').