CVE-2023-36463

Source
https://cve.org/CVERecord?id=CVE-2023-36463
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36463.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-36463
Aliases
  • GHSA-f2gp-85cr-vgj7
Published
2023-06-27T19:36:12.701Z
Modified
2026-08-12T03:51:47.353304965Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Cross site scripting (XSS) in meldekarten generator
Details

Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after submission. This issue has been addressed in commit 77e04f4af which is included in the 1.0.0b1.1.2 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36463.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "1.0.0b1.1.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/jucktnich/meldekarten-generator

Affected ranges

Type
GIT
Repo
https://github.com/jucktnich/meldekarten-generator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36463.json"