Vulnerability record · CVE-2023-0738 · published 4 April 2023
CVE-2023-0738: Orangescrum cross-site scripting vulnerability
Orangescrum · Orangescrum
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.
Description
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fluidattacks.com/advisories/eilish/ | ExploitThird Party Advisory |
| https://github.com/Orangescrum/orangescrum/ | Product |
| https://fluidattacks.com/advisories/eilish/ | ExploitThird Party Advisory |
| https://github.com/Orangescrum/orangescrum/ | Product |
Track CVE-2023-0738 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0738), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.