CVE-2023-0109
CVSS 3.0 Score 9.8 of 10 (critical)
Details
Published Nov 15, 2024
CWE ID 79
Summary
CVE-2023-0109 is a stored cross-site scripting (XSS) vulnerability affecting usememos/memos version 0.9.1. An attacker can exploit this flaw to upload a malicious JavaScript file and reference it in an HTML file. Once an user accesses the HTML file, the attacker's script is executed, potentially leading to the theft of sensitive information like login credentials. This security issue has been resolved in version 0.10.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Usememos Memos