CVE-2023-1536: high-severity vulnerability in answerdev/answer
Cross-site Scripting (XSS) - Stored in answerdev/answer
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Affected products
answerdev · answerdev/answerRelated CVEs — answerdev/answer
In the same product, most dangerous first.
CVE-2023-0744CRITICALImproper Access Control in answerdev/answerEPSS 6.4%CVE-2023-4125HIGHWeak Password Requirements in answerdev/answerEPSS 0.9%CVE-2023-0741HIGHCross-site Scripting (XSS) - DOM in answerdev/answerEPSS 0.9%CVE-2023-0742HIGHCross-site Scripting (XSS) - Stored in answerdev/answerEPSS 0.9%CVE-2023-1537MEDIUMAuthentication Bypass by Capture-replay in answerdev/answerEPSS 0.8%CVE-2023-4815HIGHMissing Authentication for Critical Function in answerdev/answerEPSS 0.8%