Code Injection in CouchDB - CVE-2023-45725
Published: December 12, 2023
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper input validation. A remote user with access to design
documents can insert specially crafted HTML code into the database and gain access to authorization or session cookie headers when the victim opens the design documents.
Affected software
Planning Analytics Local
How to mitigate CVE-2023-45725
Planning Analytics Local - addressed in versions 2.0.0.96, 2.1.3