Refine your search

2 vulnerabilities found for Citadel by Citadel

CVE-2023-44272 (GCVE-0-2023-44272)
Vulnerability from cvelistv5
Published
2023-10-04 08:07
Modified
2024-09-19 19:55
Severity ?
CWE
  • Cross-site scripting (XSS)
Summary
A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.
Impacted products
Vendor Product Version
Citadel Citadel Version: prior to 994
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T19:59:51.930Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://www.citadel.org/download.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://code.citadel.org/citadel/citadel"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://code.citadel.org/citadel/citadel/-/commit/f0dac5ff074ad686fa71ea663c8ead107bd3041e"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN08237727/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-44272",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-19T19:54:07.538323Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-19T19:55:17.251Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Citadel",
          "vendor": "Citadel",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 994"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-site scripting (XSS)",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-10-04T08:07:46.459Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "url": "https://www.citadel.org/download.html"
        },
        {
          "url": "https://code.citadel.org/citadel/citadel"
        },
        {
          "url": "https://code.citadel.org/citadel/citadel/-/commit/f0dac5ff074ad686fa71ea663c8ead107bd3041e"
        },
        {
          "url": "https://jvn.jp/en/jp/JVN08237727/"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2023-44272",
    "datePublished": "2023-10-04T08:07:46.459Z",
    "dateReserved": "2023-09-28T02:30:04.107Z",
    "dateUpdated": "2024-09-19T19:55:17.251Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

jvndb-2023-000097
Vulnerability from jvndb
Published
2023-10-04 14:07
Modified
2024-05-21 17:08
Severity ?
Summary
Citadel WebCit vulnerable to cross-site scripting on Instant Messaging facility
Details
Citadel WebCit provided by Citadel contains a cross-site scripting vulnerability (CWE-79). Tomoro Taniguchi of FiveDrive, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-000097.html",
  "dc:date": "2024-05-21T17:08+09:00",
  "dcterms:issued": "2023-10-04T14:07+09:00",
  "dcterms:modified": "2024-05-21T17:08+09:00",
  "description": "Citadel WebCit provided by Citadel contains a cross-site scripting vulnerability (CWE-79).\r\n\r\nTomoro Taniguchi of FiveDrive, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
  "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-000097.html",
  "sec:cpe": {
    "#text": "cpe:/a:citadel:citadel",
    "@product": "citadel",
    "@vendor": "citadel",
    "@version": "2.2"
  },
  "sec:cvss": [
    {
      "@score": "3.5",
      "@severity": "Low",
      "@type": "Base",
      "@vector": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
      "@version": "2.0"
    },
    {
      "@score": "5.4",
      "@severity": "Medium",
      "@type": "Base",
      "@vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "@version": "3.0"
    }
  ],
  "sec:identifier": "JVNDB-2023-000097",
  "sec:references": [
    {
      "#text": "http://jvn.jp/en/jp/JVN08237727/index.html",
      "@id": "JVN#08237727",
      "@source": "JVN"
    },
    {
      "#text": "https://www.cve.org/CVERecord?id=CVE-2023-44272",
      "@id": "CVE-2023-44272",
      "@source": "CVE"
    },
    {
      "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-44272",
      "@id": "CVE-2023-44272",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-79",
      "@title": "Cross-site Scripting(CWE-79)"
    }
  ],
  "title": "Citadel WebCit vulnerable to cross-site scripting on Instant Messaging facility"
}