View Issue Details

IDProjectCategoryView StatusLast Update
2111RackTablesdefaultpublic2026-04-24 21:11
Reporterntavares Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
Product Version0.22.0 
Summary2111: Regarding CVE-2023-49453
DescriptionRef: https://nvd.nist.gov/vuln/detail/CVE-2023-49453
Published: November 11, 2023

Claim: A Cross-Site Scripting (XSS) vulnerability in Racktables, located in the 'search' component at '/index.php?page=search', allows attackers to capture a victim's cookies through reflected Cross-Site scripting method.

Strange that there is no record of this in this bugtracker, being 2,5y old and for a seemingly simple fix.
Steps To ReproduceVerified with search string: <script>alert(1)</script>
TagsNo tags attached.

Activities

infrastation

infrastation

2026-04-24 21:11

administrator   ~0004605

I have been busy with other open source software.

Issue History

Date Modified Username Field Change
2026-04-13 13:21 ntavares New Issue
2026-04-24 21:11 infrastation Note Added: 0004605