CVE-2023-0410
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into web pages viewed by users, potentially stealing sensitive information or performing actions on their behalf. It affects versions of the qwik product before 0.1.0-beta5, and an attacker would need to trick users into visiting a compromised page to exploit it.
Technical Description
Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Jan 20, 2023
about 3 years ago
Last Modified
Mar 13, 2026
25 days ago
Vendor
qwik
Product
qwik
Related Vulnerabilities
This vulnerability allows an attacker to trick a user into performing unwanted actions on a website using the qwik framework, potentially compromising their account or data. It affects versions prior to 0.104.0 and requires the user to be logged in while visiting a malicious site.
This vulnerability allows an attacker to inject malicious code into applications built with the qwik framework, potentially leading to unauthorized access or control over the affected systems. It affects versions prior to 0.21.0, so users running older versions are at risk if they haven't updated.