Vulnerability record · CVE-2023-27293 · published 28 February 2023
CVE-2023-27293: OpenCATS questionnaire answer stored XSS via unauthenticated submission
Opencats · Opencats
OpenCATS fails to neutralize input during web page generation, letting an unauthenticated attacker store malicious JavaScript as a questionnaire answer. That script executes when an authenticated user reviews the candidate's submission, so a single crafted application can run code in a recruiter's browser session.
Description
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityUnauthenticated stored XSS with public exploit references and very high EPSS, though it requires victim interaction and yields limited direct confidentiality and integrity impact.
What it is
OpenCATS fails to neutralize input during web page generation, letting an unauthenticated attacker store malicious JavaScript as a questionnaire answer. That script executes when an authenticated user reviews the candidate's submission, so a single crafted application can run code in a recruiter's browser session.
Impact
An attacker can steal other users' cookies and force authenticated users to perform actions without their knowledge, potentially leading to session hijacking or unauthorized changes in the application.
Attack surface
Reached over the network through the questionnaire submission flow, which requires no authentication; exploitation requires the victim to view the malicious submission, so user interaction is needed. The CVSS vector confirms AV:N, PR:N and UI:R.
Exploitation
No CISA KEV listing, but EPSS is 0.57043 (99th percentile) and both references are tagged Exploit, indicating public exploit detail exists and exploitation is plausible.
What to do
- Apply the vendor fix for OpenCATS once available; check the OpenCATS project for a patched release addressing this XSS.
- If no patch is available, sanitize or encode all questionnaire answer input on output and reject HTML/script content.
- Enforce a strict Content-Security-Policy to limit script execution in the recruiter interface.
- Set session cookies HttpOnly and Secure to reduce cookie theft impact.
- Restrict or review access to candidate submission review pages until the issue is fixed.
Detection
- Search web and application logs for questionnaire submissions containing script tags, event handlers, or javascript: URIs.
- Monitor for anomalous outbound requests or cookie exfiltration patterns from recruiter sessions after reviewing submissions.
- Alert on unexpected account actions or privilege changes performed by authenticated users shortly after viewing candidate submissions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2023-8 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2023-8 | ExploitThird Party Advisory |
Track CVE-2023-27293 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27293), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.