View Issue Details

IDProjectCategoryView StatusLast Update
2111RackTablesdefaultpublic2026-04-13 13:21
Reporterntavares Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
Product Version0.22.0 
Summary2111: Regarding CVE-2023-49453
DescriptionRef: https://nvd.nist.gov/vuln/detail/CVE-2023-49453
Published: November 11, 2023

Claim: A Cross-Site Scripting (XSS) vulnerability in Racktables, located in the 'search' component at '/index.php?page=search', allows attackers to capture a victim's cookies through reflected Cross-Site scripting method.

Strange that there is no record of this in this bugtracker, being 2,5y old and for a seemingly simple fix.
Steps To ReproduceVerified with search string: <script>alert(1)</script>
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-04-13 13:21 ntavares New Issue