Stored cross site scripting in changedetection.io
Moderate severity
GitHub Reviewed
Published
Feb 18, 2023
to the GitHub Advisory Database
•
Updated Mar 19, 2025
Description
Published by the National Vulnerability Database
Feb 17, 2023
Published to the GitHub Advisory Database
Feb 18, 2023
Reviewed
Jun 12, 2023
Last updated
Mar 19, 2025
Changedetection.io before 0.40.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
References