Stored cross site scripting in changedetection.io
Moderate severity
GitHub Reviewed
Published
Feb 18, 2023
to the GitHub Advisory Database
•
Updated Sep 6, 2024
Description
Published by the National Vulnerability Database
Feb 17, 2023
Published to the GitHub Advisory Database
Feb 18, 2023
Reviewed
Jun 12, 2023
Last updated
Sep 6, 2024
Changedetection.io before 0.40.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
References