changedetection.io through 0.60.6 Cross-Site Scripting via watch_title
28Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 2.3epss 0.2%
probabilidad de explotación
0.2%top 87% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
dgtlmoon · changedetection.ioPoCs públicas encontradas — 1
cve_referencegithub.com/geo-chen/oss/blob/main/changedetection.io.md#finding-1-stored-htmlmarkup-injection-into-html-notifications-via-scraped-page-title-watch_title-not-in-the-escape-setno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/dgtlmoon/changedetection.iohttps://github.com/dgtlmoon/changedetection.io/blob/0.60.6/changedetectionio/notification/handler.py#L400-L414https://github.com/geo-chen/oss/blob/main/changedetection.io.md#finding-1-stored-htmlmarkup-injection-into-html-notifications-via-scraped-page-title-watch_title-not-in-the-escape-sethttps://www.vulncheck.com/advisories/changedetection-io-through-0.60.6-cross-site-scripting-via-watch-title