ZeroHour

CVE-2023-0624

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p40
Published
()
Modified
Description

OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.

Vendors
orangescrum
Products
orangescrum
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.