CVE-2023-5556
CVSS 3.1 Score 6.1 of 10 (medium)
Attack Complexity low
Scope changed
Confidentiality low
Integrity low
Availability none
Privileges Required none
Details
Published Oct 12, 2023
Updated: Oct 16, 2023
CWE ID 79
Summary
CVE-2023-5556 is a Cross-Site Scripting (XSS) vulnerability affecting the GitHub repository structurizr/onpremises before version 3194. An attacker can exploit this flaw by injecting malicious scripts into a user's browser, potentially stealing sensitive information or taking control of user actions. The vulnerability is reflected, meaning the attacker does not require any user interaction beyond visiting a specially crafted webpage, making it particularly dangerous. Users are urged to update to the latest version of the repository to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share