Junglewise Threat Intelligence

CVE-2023-24769: PYSEC-2023-10 - Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulne

CVE-2023-24769 · Severity: low · CVSS 3.1 · Published 2023-02-17

Technologies: changedetection.io (PyPI). Vendors: PyPI.

Executive brief

Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.

Affected products

  • PyPI changedetection.io

Related threats