Vulnerability CVE-2023-33829


Published: 2023-05-24

Description:
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.

See advisories in our WLB2 database:
Topic
Author
Date
Low
SCM Manager 1.60 Cross Site Scripting
neg0x
28.05.2023

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://bitbucket.org/sdorra/docker-scm-manager/src/master/
https://github.com/n3gox/Stored-XSS-on-SCM-Manager-1.60

Copyright 2024, cxsecurity.com

 

Back to Top