CVE-2023-45908
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 79
Summary
CVE-2023-45908 is a stored cross-site scripting (XSS) vulnerability affecting Homarr before version 0.14.0. An attacker can exploit this flaw by injecting malicious scripts into a Notebook widget, which is then stored and executed on the affected site whenever the affected page is loaded. The vulnerability poses a significant risk as the scripts can steal sensitive information or take control of user sessions. To mitigate this risk, users are advised to upgrade to the latest version of Homarr as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.