CVE-2023-0287
Published on: Not Yet Published
Last Modified on: 01/23/2023 06:32:00 PM UTC
Certain versions of Favorites-web from Favorites-web Project contain the following vulnerability:
A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218294 is the identifier assigned to this vulnerability.
- CVE-2023-0287 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
ityouknow - favorites-web version = n/a
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
vuldb.com text/plain Inactive LinkNot Archived |
![]() | |
vuldb.com text/plain Inactive LinkNot Archived |
![]() | |
进行评论时存在存储型xss漏洞 · Issue #I684L9 · 纯洁的微笑/favorites-web - Gitee.com | gitee.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Favorites-web Project | Favorites-web | - | All | All | All |
- cpe:2.3:a:favorites-web_project:favorites-web:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-0287 : A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by… twitter.com/i/web/status/1… | 2023-01-13 13:03:56 |