Vulnerability record · CVE-2023-0028 · published 1 January 2023
CVE-2023-0028: Twake stored XSS in linagora/twake before 2023.Q1.1200+
Linagora · Twake
Twake (linagora/twake) contains a stored cross-site scripting flaw prior to version 2023.Q1.1200+. Injected script is persisted and later rendered to other users, so a low-privileged user can plant code that executes in victims' browsers. The record gives no further detail on the vulnerable component or input path.
Description
Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityPublic exploit material and a very high EPSS score raise the likelihood of exploitation despite the medium CVSS rating.
What it is
Twake (linagora/twake) contains a stored cross-site scripting flaw prior to version 2023.Q1.1200+. Injected script is persisted and later rendered to other users, so a low-privileged user can plant code that executes in victims' browsers. The record gives no further detail on the vulnerable component or input path.
Impact
An attacker can run script in the context of other users' sessions, enabling session or data theft and actions performed as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with low privileges required (PR:L) and user interaction needed (UI:R), consistent with a stored XSS payload viewed by a victim. No authentication bypass is implied; the attacker needs a valid low-privileged account.
Exploitation
Not listed in CISA KEV, but EPSS is 0.56018 (99th percentile) and a reference is tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Upgrade Twake to 2023.Q1.1200+ or later, applying the patch commit c0708c397e199c68cea0db9f59d29d7dbdcdde7b.
- Enforce output encoding and input sanitization for all user-supplied content rendered in Twake.
- Deploy a Content Security Policy that blocks inline and untrusted script execution.
- Restrict who can post content that is rendered to other users until patching is complete.
Detection
- Search application and web logs for stored payload patterns such as <script> or event handler attributes in user content.
- Monitor for anomalous client-side requests or session activity originating from Twake pages.
- Review CSP violation reports for blocked inline script execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/linagora/Twake/pull/2678/commits/c0708c397e199c68cea0db9f59d29d7dbdcdde7b | Patch |
| https://huntr.dev/bounties/bfd935f4-2d1d-4d3f-8b59-522abe7dd065 | ExploitPatchThird Party Advisory |
| https://github.com/linagora/Twake/pull/2678/commits/c0708c397e199c68cea0db9f59d29d7dbdcdde7b | Patch |
| https://huntr.dev/bounties/bfd935f4-2d1d-4d3f-8b59-522abe7dd065 | ExploitPatchThird Party Advisory |
Track CVE-2023-0028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0028), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.