TROYANOSYVIRUS
Back to CVEs

CVE-2023-4892

MEDIUM
5.7

Description

Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate. Thanks to this, it is possible to execute malicious JavaScript in the webapp.

CVE Details

CVSS v3.1 Score5.7
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published9/25/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

sismics:teedy

Weaknesses (CWE)

CWE-79CWE-79

References

https://teedy.io(help@fluidattacks.com)
https://fluidattacks.com/advisories/freebird(af854a3a-2127-422b-91ae-364da2661108)
https://teedy.io(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.