herombey/CVE-2023-47437

herombey/CVE-2023-47437

Releases0
Vulnerability Disclosure

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables an attacker to inject malicious java script.