CVE-2023-0028
medium · 5.7Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
5.7
CVSS
56.0%
EPSS (exploit prob.)
99th
EPSS percentile
2023-01-01
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:H
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| linagora | twake | <= 2022.q4.1120 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/linagora/Twake/pull/2678/commits/c0708c397e199c68cea0db9f59d29d7dbdcdde7b
- https://huntr.dev/bounties/bfd935f4-2d1d-4d3f-8b59-522abe7dd065
- https://github.com/linagora/Twake/pull/2678/commits/c0708c397e199c68cea0db9f59d29d7dbdcdde7b
- https://huntr.dev/bounties/bfd935f4-2d1d-4d3f-8b59-522abe7dd065
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-0028