CVE-2023-41316
Last modified
CVE-2023-41316 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML ends up in invitation emails which appear as legitimate org invitations. Bad actors may direct users to malicious website or execute javascript in the context of the users browser. This vulnerability has been addressed in version 3.29.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tolgee | Tolgee | < 3.29.2 |
References
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-gx3w-rwh5-w5cgExploit, Vendor Advisory
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-gx3w-rwh5-w5cgExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41316?
How severe is CVE-2023-41316?
How do I fix CVE-2023-41316?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4131Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-41310Keep-alive vulnerability in the sticky broadcast mechanism. …3.3
- CVE-2023-41311Permission control vulnerability in the audio module. Succes…5.3
- CVE-2023-41312Permission control vulnerability in the audio module. Succes…5.3
- CVE-2023-41313The authentication method in Apache Doris versions before 2.…9.8
- CVE-2023-41314The api /api/snapshot and /api/get_log_file would allow unau…8.2
- CVE-2023-41317The Apollo Router is a configurable, high-performance graph …5.9
- CVE-2023-41318matrix-media-repo is a highly customizable multi-domain medi…5.4
- CVE-2023-41319Fides is an open-source privacy engineering platform for man…7.2
- CVE-2023-4132A use-after-free vulnerability was found in the siano smsusb…5.5
- CVE-2023-41320GLPI stands for Gestionnaire Libre de Parc Informatique is a…9.8
- CVE-2023-41321GLPI stands for Gestionnaire Libre de Parc Informatique is a…6.5
Are you affected by CVE-2023-41316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
