SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4892

Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate.

MEDIUM 4.6EPSS 0.39%

Does this matter?

Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.

Description

Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker could manipulate. Thanks to this, it is possible to execute malicious JavaScript in the webapp.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
EPSS
0.39% probability · 32th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
sismics/teedy
Source
help@fluidattacks.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.