Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3199 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0. |
Github GHSA |
GHSA-5r2g-59px-3q9w | Stored XSS using two files in usememos/memos |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 20 Nov 2024 00:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:usememos:memos:0.9.1:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Sat, 16 Nov 2024 06:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usememos
Usememos memos |
|
| CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
|
| Metrics |
ssvc
|
Fri, 15 Nov 2024 20:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0. | |
| Title | Stored XSS in usememos/memos | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-11-15T20:56:59.319Z
Reserved: 2023-01-07T02:52:45.260Z
Link: CVE-2023-0109
Updated: 2024-11-15T20:56:52.465Z
Status : Analyzed
Published: 2024-11-15T11:15:08.097
Modified: 2024-11-19T14:44:24.977
Link: CVE-2023-0109
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA