VulnerabilityModified
CVE-2023-4892
Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate.
MEDIUM 4.6EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate. Thanks to this, it is possible to execute malicious JavaScript in the webapp.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sismics/teedy
- Source
- help@fluidattacks.com
References
- https://fluidattacks.com/advisories/freebirdExploit, Third Party Advisory
- https://teedy.ioProduct
- https://fluidattacks.com/advisories/freebirdExploit, Third Party Advisory
- https://teedy.ioProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.