CVE-2023-30790
CVSS V2 None
CVSS V3 None
Description
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
Overview
- CVE ID
- CVE-2023-30790
- Assigner
- help@fluidattacks.com
- Vulnerability Status
- Received
- Published Version
- 2023-05-08T20:15:20
- Last Modified Date
- 2023-05-08T20:15:20
References
Reference URL | Reference Tags |
---|---|
https://fluidattacks.com/advisories/napoli | |
https://www.monicahq.com/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-30790 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-30790 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-08 21:05:58 | Added to TrackCVE |