← Vulnerability feed

Vulnerability record · CVE-2023-27293 · published 28 February 2023

CVE-2023-27293: OpenCATS questionnaire answer stored XSS via unauthenticated submission

Opencats · Opencats

OpenCATS fails to neutralize input during web page generation, letting an unauthenticated attacker store malicious JavaScript as a questionnaire answer. That script executes when an authenticated user reviews the candidate's submission, so a single crafted application can run code in a recruiter's browser session.

6.1 CVSS 3.1 Medium EPSS 57% · top 1.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated stored XSS with public exploit references and very high EPSS, though it requires victim interaction and yields limited direct confidentiality and integrity impact.

What it is

OpenCATS fails to neutralize input during web page generation, letting an unauthenticated attacker store malicious JavaScript as a questionnaire answer. That script executes when an authenticated user reviews the candidate's submission, so a single crafted application can run code in a recruiter's browser session.

Impact

An attacker can steal other users' cookies and force authenticated users to perform actions without their knowledge, potentially leading to session hijacking or unauthorized changes in the application.

Attack surface

Reached over the network through the questionnaire submission flow, which requires no authentication; exploitation requires the victim to view the malicious submission, so user interaction is needed. The CVSS vector confirms AV:N, PR:N and UI:R.

Exploitation

No CISA KEV listing, but EPSS is 0.57043 (99th percentile) and both references are tagged Exploit, indicating public exploit detail exists and exploitation is plausible.

What to do

  • Apply the vendor fix for OpenCATS once available; check the OpenCATS project for a patched release addressing this XSS.
  • If no patch is available, sanitize or encode all questionnaire answer input on output and reject HTML/script content.
  • Enforce a strict Content-Security-Policy to limit script execution in the recruiter interface.
  • Set session cookies HttpOnly and Secure to reduce cookie theft impact.
  • Restrict or review access to candidate submission review pages until the issue is fixed.

Detection

  • Search web and application logs for questionnaire submissions containing script tags, event handlers, or javascript: URIs.
  • Monitor for anomalous outbound requests or cookie exfiltration patterns from recruiter sessions after reviewing submissions.
  • Alert on unexpected account actions or privilege changes performed by authenticated users shortly after viewing candidate submissions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27293 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-48011Opencats sql injection vulnerabilityOpencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.EPSS 1.1%9.8CVE-2022-43019Opencats deserialization of untrusted data vulnerabilityOpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.EPSS 2.1%9.8CVE-2021-41560Opencats unrestricted file upload vulnerabilityOpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.EPSS 11%9.8CVE-2021-25294Opencats deserialization of untrusted data vulnerabilityOpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php …EPSS 11%7.5CVE-2019-13358Opencats xml external entity (xxe) vulnerabilitylib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker mus…EPSS 24%6.5CVE-2022-43023Opencats sql injection vulnerabilityOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.EPSS 0.86%6.5CVE-2022-43020Opencats sql injection vulnerabilityOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.EPSS 0.86%6.5CVE-2022-43021Opencats sql injection vulnerabilityOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2023-27293), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.