CVE-2023-48226
MEDIUMOpenReplay < 1.15.0 - HTML Injection in Account Settings Name Field
Title source: llmDescription
OpenReplay is a self-hosted session replay suite. In version 1.14.0, due to lack of validation Name field - Account Settings (for registration looks like validation is correct), a bad actor can send emails with HTML injected code to the victims. Bad actors can use this to phishing actions for example. Email is really send from OpenReplay, but bad actors can add there HTML code injected (content spoofing). Please notice that during Registration steps for FullName looks like is validated correct - can not type there, but using this kind of bypass/workaround - bad actors can achieve own goal. As of time of publication, no known fixes or workarounds are available.
References (5)
Core 5
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/openreplay/openreplay/security/advisories/GHSA-xpfv-454c-3fj4
Third Party Advisory x_refsource_misc
https://bugcrowd.com/vulnerability-rating-taxonomy
Technical Description x_refsource_misc
https://capec.mitre.org/data/definitions/242.html
Technical Description x_refsource_misc
https://cwe.mitre.org/data/definitions/20.html
Scores
CVSS v3
6.5
EPSS
0.0078
EPSS Percentile
51.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
CWE-94
Status
published
Products (1)
openreplay/openreplay
< 1.15.0
Published
Nov 21, 2023
Tracked Since
Feb 18, 2026