Record summary

CVE-2023-1496 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 3.14.0affected

github.com/imgproxy/imgproxy/v3

Browse Go / github.com/imgproxy/imgproxy/v3
GitHub AdvisoryBefore 3.14.0 · Fixed in 3.14.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMImgproxy < 3.14.0 - Cross-site Scripting (XSS)CVSS 5.4

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.

Remediation

Upgrade to Imgproxy version 3.14.0 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorspdteam
Template tagscvecve2023huntrimgproxyxsssvgevilmartiansvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:evilmartians:imgproxy:*:*:*:*:*:*:*:*
Shodan: Server: imgproxy
Shodan: server: imgproxy

Source: ProjectDiscovery

References

4