CVE-2023-46475: XSS
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46475 vulnerability?
CVE-2023-46475 is a Stored Cross-Site Scripting vulnerability in ZenTao 18.3, allowing users to inject malicious JavaScript code in the name field of a project.
How can an attacker exploit CVE-2023-46475?
An attacker can exploit CVE-2023-46475 by creating a project in ZenTao 18.3 and injecting malicious JavaScript code in the project's name field.
What is the severity of CVE-2023-46475?
CVE-2023-46475 has a severity value of 5.4, which is considered medium.
How can I fix CVE-2023-46475 vulnerability?
To fix CVE-2023-46475, you should update to a version of ZenTao that has patched the vulnerability.
Where can I find more information about CVE-2023-46475?
You can find more information about CVE-2023-46475 in the references provided, such as the GitHub links.