CVE-2023-46499: XSS
Published Dec 8, 2023
·Updated
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.
Affected Software
10 affected componentsFixes available
npm/@evershop/evershop<1.0.0-rc.5
1.0.0-rc.5
evershop Evershop Node.js=1.0.0-beta
evershop Evershop Node.js=1.0.0-beta1
evershop Evershop Node.js=1.0.0-beta2
evershop Evershop Node.js=1.0.0-beta3
evershop Evershop Node.js=1.0.0-beta4
evershop Evershop Node.js=1.0.0-beta5
evershop Evershop Node.js=1.0.0-rc1
evershop Evershop Node.js=1.0.0-rc2
evershop Evershop Node.js=1.0.0-rc3
Event History
Dec 8, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-46499?
CVE-2023-46499 is classified as a medium severity cross site scripting vulnerability.
2
How do I fix CVE-2023-46499?
To fix CVE-2023-46499, update to EverShop NPM version 1.0.0-rc.5 or later.
3
Which versions of EverShop are affected by CVE-2023-46499?
CVE-2023-46499 affects all versions of EverShop NPM before 1.0.0-rc.5.
4
Can CVE-2023-46499 lead to sensitive information exposure?
Yes, CVE-2023-46499 can allow a remote attacker to obtain sensitive information from the Admin Panel.
5
What type of vulnerability is CVE-2023-46499?
CVE-2023-46499 is a cross site scripting vulnerability that allows execution of crafted scripts.