6.1
CVSSv3

CVE-2023-26777

Published: 04/04/2023 Updated: 11/04/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote malicious user to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.

Vulnerable Product Search on Vulmon Subscribe to Product

uptime kuma project uptime kuma

Exploits

Uptime Kuma versions 1196 and below suffer from a cross site scripting vulnerability ...