github.com
https://github.com/imgproxy/imgproxy CVE-2023-1496
MEDIUMNuclei
Cross-site Scripting (XSS) - Reflected in imgproxy/imgproxy
Record summary
CVE-2023-1496 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
imgproxy/imgproxyBrowse imgproxy / imgproxy/imgproxy | CVE List | Before 3.14.0 | affected |
github.com/imgproxy/imgproxy/v3Browse Go / github.com/imgproxy/imgproxy/v3 | GitHub Advisory | Before 3.14.0 · Fixed in 3.14.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMImgproxy < 3.14.0 - Cross-site Scripting (XSS)CVSS 5.4
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.
Remediation
Upgrade to Imgproxy version 3.14.0 or later to mitigate this vulnerability.
WeaknessesCWE-79
Authorspdteam
Template tagscvecve2023huntrimgproxyxsssvgevilmartiansvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:evilmartians:imgproxy:*:*:*:*:*:*:*:*
Shodan: Server: imgproxy
Shodan: server: imgproxy
https://github.com/imgproxy/imgproxy/commit/62f8d08a93d301285dcd1dabcc7ba10c6c65b689 https://huntr.dev/bounties/de603972-935a-401a-96fb-17ddadd282b2
Source: ProjectDiscovery
References
4github.com
https://github.com/imgproxy/imgproxy/commit/62f8d08a93d301285dcd1dabcc7ba10c6c65b689 huntr.dev
https://huntr.dev/bounties/de603972-935a-401a-96fb-17ddadd282b2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-1496