GSD-2023-1001657

Source
https://data.gsd.id/GSD-2023-1001657
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2023/1001xxx/GSD-2023-1001657.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2023-1001657
Withdrawn
2023-03-14T07:01:09.296630Z
Published
2023-01-19T17:20:01.004554Z
Modified
2023-03-14T07:01:09.296630Z
Summary
XSS in website version all current versions
Details

In the ZeroSSL website https://app.zerossl.com an XSS exists in it that can be attacked via phishing resulting in theft of private certificate keys, hashed password and/or session hijacking. It is not clear if the vendor has fixed this issue or not at this time.

References

Affected packages