Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.
References
Link | Resource |
---|---|
https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-c9cx-ghwr-x58m | Vendor Advisory |
https://claroty.com/team82/disclosure-dashboard | Issue Tracking Third Party Advisory |
https://xibosignage.com/blog/security-advisory-2023-05/ | Vendor Advisory |
Configurations
History
06 Jun 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://xibosignage.com/blog/security-advisory-2023-05/ - Vendor Advisory | |
References | (MISC) https://claroty.com/team82/disclosure-dashboard - Issue Tracking, Third Party Advisory | |
References | (MISC) https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-c9cx-ghwr-x58m - Vendor Advisory | |
First Time |
Xibosignage xibo
Xibosignage |
|
CWE | CWE-209 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:* |
30 May 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-30 21:15
Updated : 2023-06-06 01:15
NVD link : CVE-2023-33181
Mitre link : CVE-2023-33181
JSON object : View
Products Affected
xibosignage
- xibo
CWE
CWE-209
Generation of Error Message Containing Sensitive Information