#VU84347 Code Injection in CouchDB - CVE-2023-45725
Published: December 12, 2023
CouchDB
Apache Foundation
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper input validation. A remote user with access to design
documents can insert specially crafted HTML code into the database and gain access to authorization or session cookie headers when the victim opens the design documents.