Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ev3Rr3D

#49148of 56,338
5.4Total CVSS
Vulnerabilities · 1
PT-2023-31568
5.4
2023-12-10
Monica · Monica · CVE-2023-50465
**Name of the Vulnerable Software and Affected Versions** Monica (aka MonicaHQ) version 4.0.0 **Description** A stored cross-site scripting (XSS) vulnerability exists in the software via an SVG document uploaded by an authenticated user. **Recommendations** For version 4.0.0, consider restricting the upload of SVG documents by authenticated users until a patch is available. As a temporary workaround, disabling the feature to upload SVG files can help minimize the risk of exploitation.