CVE-2023-1496 is a reflected Cross-site Scripting (XSS) vulnerability affecting imgproxy/imgproxy versions prior to 3.14.0. Rated Medium with a CVSS score of 5.4, it requires low privileges and user interaction, allowing an attacker to execute malicious scripts in the victim's browser, potentially leading to low confidentiality and integrity impacts. While not on CISA's KEV catalog, this vulnerability is on the "Hot List" and has publicly available Nuclei templates, indicating active community interest and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.14.0CPE matchmatch criteria | cpe:2.3:a:evilmartians:imgproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.