Vulnerability Database
Blog
FAQ
Docs
GHSA-jm3m-wr3p-hjrq
Suggest an improvement
Source
https://github.com/advisories/GHSA-jm3m-wr3p-hjrq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-jm3m-wr3p-hjrq/GHSA-jm3m-wr3p-hjrq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jm3m-wr3p-hjrq
Aliases
CVE-2023-0519
PYSEC-2023-31
Published
2023-01-27T00:30:18Z
Modified
2024-09-24T21:03:43.531063Z
Severity
7.1 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS Calculator
5.1 (Medium)
CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Calculator
Summary
Cross-site Scripting in modoboa
Details
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
References
https://nvd.nist.gov/vuln/detail/CVE-2023-0519
https://github.com/modoboa/modoboa/commit/eef9ab72b5305578a3ad7a7463bd284aa645e98b
https://github.com/modoboa/modoboa
https://github.com/pypa/advisory-database/tree/main/vulns/modoboa/PYSEC-2023-31.yaml
https://huntr.dev/bounties/891ad0cb-d12f-4c5e-aac8-d7326caf2129
Affected packages
PyPI
/
modoboa
Package
Name
modoboa
View open source insights on deps.dev
Purl
pkg:pypi/modoboa
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.0.4
Affected versions
0.*
0.7.0
1.*
1.2.0-rc2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.11.0
1.11.1
1.12.0
1.12.1
1.12.2
1.13.0
1.13.1
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
2.*
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0
2.0.1
2.0.2
2.0.3
GHSA-jm3m-wr3p-hjrq - OSV