Impact
The affected application, changedetection.io versions up to 0.60.6, contains a stored cross-site scripting vulnerability. A watched page title is rendered into HTML notifications without escaping, so an attacker can inject arbitrary markup into the watch_title token that appears in notification templates. If the notification is sent to channels that render HTML, such as email or Telegram, the injected markup can execute scripts or otherwise damage the experience of recipients. The consequence is a compromise of confidentiality and integrity for anyone receiving the notification, and the weakness is identified as CWE‑79.
Affected Systems
The vulnerability exists in changedetection.io, a web-based monitoring tool published by dgtlmoon. Versions up to and including 0.60.6 are impacted. Newer versions are not indicated as vulnerable.
Risk and Exploitability
With a CVSS score of 2.3 the severity is low, and the EPSS score of less than 1 % combined with the absence of a KEV listing suggests that exploitation is currently unlikely. The likely attack vector involves the attacker supplying a monitored page with a malicious title, or otherwise manipulating the watch_title field that is inserted into the notification template. If successful, the attacker can deliver malicious content to users who view the notification, potentially compromising their browsers or triggering unauthorized actions. The environment therefore poses low but real risk if the monitoring settings can be controlled by attackers.
OpenCVE Enrichment