Pachno 1.0.6 Authenticated XSS via Project Description/Comments
CVE-2023-47437 Published on November 28, 2023
A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables an attacker to inject malicious java script.
Products Associated with CVE-2023-47437
Want to know whenever a new CVE is published for Pachno? stack.watch will email you.
Exploit Probability
EPSS
0.13%
Percentile
31.52%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.