CVE-2023-2848

HIGH

Movim <0.22 - XSS

Title source: llm

Description

Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.

Scores

CVSS v3 8.0
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Classification

CWE
CWE-346 CWE-1385
Status published

Affected Products (1)

movim/movim < 0.22

Timeline

Published Sep 14, 2023
Tracked Since Feb 18, 2026