NA

CVE-2023-1767

Published: 20/04/2023 Updated: 28/04/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

The Snyk Advisor website (snyk.io/advisor/) was vulnerable to a stored XSS before 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned package's Readme on its package health page. An attacker could create a package in NPM with an associated markdown README file containing XSS-able HTML tags. Upon Snyk Advisor importing the package, the XSS would run each time an end user browsed to the package's page on Snyk Advisor.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

snyk advisor

Github Repositories

Stored XSS snykio Discovery (19/03/23) CVE-2023-1767 Responsible Vulnerability Disclosure Report Vulnerability blog post coverage Exploit PoC