Vulnerability Description
2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested in docker-compose environment. This vulnerability has been patched in version 4.0.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 2Fauth | 2Fauth | < 4.0.3 |
Related Weaknesses (CWE)
References
- https://github.com/Bubka/2FAuth/releases/tag/v4.0.3Release Notes
- https://github.com/Bubka/2FAuth/security/advisories/GHSA-cwhq-2mcq-pp9qExploitVendor Advisory
- https://github.com/Bubka/2FAuth/releases/tag/v4.0.3Release Notes
- https://github.com/Bubka/2FAuth/security/advisories/GHSA-cwhq-2mcq-pp9qExploitVendor Advisory
FAQ
What is CVE-2023-36816?
CVE-2023-36816 is a vulnerability with a CVSS score of 6.1 (MEDIUM). 2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested i...
How severe is CVE-2023-36816?
CVE-2023-36816 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36816?
Check the references section above for vendor advisories and patch information. Affected products include: 2Fauth 2Fauth.