T
eedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate. Thanks to this, it is possible to execute malicious JavaScript in the webapp.
References
| Link | Resource |
|---|---|
| https://fluidattacks.com/advisories/freebird | Exploit Third Party Advisory |
| https://teedy.io | Product |
| https://fluidattacks.com/advisories/freebird | Exploit Third Party Advisory |
| https://teedy.io | Product |
Configurations
History
21 Nov 2024, 08:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fluidattacks.com/advisories/freebird - Exploit, Third Party Advisory | |
| References | () https://teedy.io - Product | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.7 |
Information
Published : 2023-09-25 16:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-4892
Mitre link : CVE-2023-4892
CVE.ORG link : CVE-2023-4892
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')