CVE-2023-46494: XSS
Published Dec 8, 2023
·Updated
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid function in admin/productGrid/Grid.jsx.
Affected Software
10 affected componentsFixes available
npm/@evershop/evershop<1.0.0-rc.5
1.0.0-rc.5
evershop Evershop Node.js=1.0.0-beta
evershop Evershop Node.js=1.0.0-beta1
evershop Evershop Node.js=1.0.0-beta2
evershop Evershop Node.js=1.0.0-beta3
evershop Evershop Node.js=1.0.0-beta4
evershop Evershop Node.js=1.0.0-beta5
evershop Evershop Node.js=1.0.0-rc1
evershop Evershop Node.js=1.0.0-rc2
evershop Evershop Node.js=1.0.0-rc3
Event History
Dec 8, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-46494?
CVE-2023-46494 is classified as a Cross Site Scripting vulnerability that can lead to sensitive information exposure.
2
How do I fix CVE-2023-46494?
To fix CVE-2023-46494, update your EverShop NPM package to version 1.0.0-rc.5 or later.
3
Which versions are affected by CVE-2023-46494?
CVE-2023-46494 affects EverShop NPM versions prior to v.1.0.0-rc.5.
4
Can CVE-2023-46494 be exploited remotely?
Yes, CVE-2023-46494 allows a remote attacker to exploit the vulnerability via a crafted request.
5
What components of EverShop are vulnerable to CVE-2023-46494?
The vulnerability CVE-2023-46494 primarily affects the ProductGrid function in admin/productGrid/Grid.jsx.