Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3199 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0. |
Github GHSA |
GHSA-5r2g-59px-3q9w | Stored XSS using two files in usememos/memos |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 19 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:usememos:memos:0.9.1:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 15 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usememos
Usememos memos |
|
| CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
|
| Metrics |
ssvc
|
Fri, 15 Nov 2024 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0. | |
| Title | Stored XSS in usememos/memos | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-11-15T20:56:59.319Z
Reserved: 2023-01-07T02:52:45.260Z
Link: CVE-2023-0109
Updated: 2024-11-15T20:56:52.465Z
Status : Analyzed
Published: 2024-11-15T11:15:08.097
Modified: 2024-11-19T14:44:24.977
Link: CVE-2023-0109
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA