CVE-2023-45815 describes a cross-site scripting (XSS) vulnerability in ArchiveBox, an open-source web archiving system, specifically when using the 'wget' extractor. An attacker could craft a malicious archived page that, when viewed by a logged-in administrator in the same browser session, could execute arbitrary JavaScript. This could lead to unauthorized modification of snapshots, user accounts, or other administrative actions within ArchiveBox. The vulnerability has a CVSS score of 5.4 MEDIUM, indicating a moderate severity. It requires user interaction (viewing a malicious page) and a logged-in session for maximum impact, but can still read other archived content for non-logged-in users. The issue stems from archived content and the admin panel sharing the same host and port, bypassing typical browser security. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. A patch is under development, and mitigations include disabling the wget extractor, ensuring users are logged out, or serving a static HTML version of the archive.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.6.2CPE matchmatch criteria | cpe:2.3:a:archivebox:archivebox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.