CVE-2023-52265: XSS
Published Dec 30, 2023
·Updated
IDURAR (aka idurar-erp-crm) through 2.0.1 allows stored XSS via a PATCH request with a crafted JSON email template in the /api/email/update data.
Affected Software
1 affected component
Idurarapp Idurar<=2.0.1
Remediation
Event History
Dec 30, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52265?
CVE-2023-52265 has a severity rating that allows for the exploitation of stored XSS vulnerabilities which can lead to significant security risks.
2
How do I fix CVE-2023-52265?
To fix CVE-2023-52265, upgrade the Idurar application to version 2.1.0 or higher.
3
What types of attacks can CVE-2023-52265 enable?
CVE-2023-52265 can enable attackers to execute arbitrary JavaScript in the context of users accessing the application.
4
Which versions of Idurar are affected by CVE-2023-52265?
CVE-2023-52265 affects all versions of Idurar up to and including version 2.0.1.
5
Is there any workaround for CVE-2023-52265?
There is no specific workaround for CVE-2023-52265, and it is recommended to apply the software update as soon as possible.