CVE-2023-24769
17.02.2023, 22:15
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
Vendor | Product | Version |
---|---|---|
changedetection | changedetection | 𝑥 < 0.40.1.1 |
𝑥
= Vulnerable software versions
References