Bug 1216204 (CVE-2023-5564) - VUL-0: CVE-2023-5564: froxlor: HTML injection Leads to Open redirection
Summary: VUL-0: CVE-2023-5564: froxlor: HTML injection Leads to Open redirection
Status: RESOLVED WONTFIX
Alias: CVE-2023-5564
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/381764/
Whiteboard:
Keywords:
Depends on:
Blocks: CVE-2023-4829
  Show dependency treegraph
 
Reported: 2023-10-13 07:46 UTC by SMASH SMASH
Modified: 2023-12-08 12:52 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-10-13 07:46:20 UTC
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior
to 2.1.0-dev1.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5564
https://huntr.dev/bounties/9254d8f3-a847-4ae8-8477-d2ce027cff5c/
https://github.com/froxlor/froxlor/commit/e8ed43056c1665522a586e3485da67f2bdf073aa
Comment 1 Robert Frohl 2023-10-13 08:52:06 UTC
might be relevant for Backports, the version is quite old though. Not easy to very.

Maybe worth to drop froxlor from Backports for 15.6 as there are quite a few CVEs and no active maintainer anymore ?
Comment 2 Max Lin 2023-10-19 06:55:49 UTC
it has been deleted in openSUSE:Backports:SLE-15-SP6 via https://build.opensuse.org/request/show/1103489 , we should not ship it anymore in Leap 15.6.