{ "id": "CVE-2023-38970", "sourceIdentifier": "cve@mitre.org", "published": "2023-08-30T22:15:08.717", "lastModified": "2023-08-31T10:02:10.690", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function." } ], "metrics": {}, "references": [ { "url": "https://github.com/anh91/uasoft-indonesia--badaso/blob/main/XSS3.md", "source": "cve@mitre.org" }, { "url": "https://panda002.hashnode.dev/badaso-version-297-has-an-xss-vulnerability-in-new-member", "source": "cve@mitre.org" } ] }