Vulnerability Details CVE-2023-29015
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of malicious script code in the user's browser when displaying the comment. The vulnerability has been fixed in version 23.03.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.1%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-29015
-
cpe:2.3:a:intranda:goobi_viewer_core:21.01
-
cpe:2.3:a:intranda:goobi_viewer_core:21.01.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.01.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.01.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.01.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.01.5
-
cpe:2.3:a:intranda:goobi_viewer_core:21.02
-
cpe:2.3:a:intranda:goobi_viewer_core:21.02.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.02.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.02.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.02.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.03
-
cpe:2.3:a:intranda:goobi_viewer_core:21.03.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.03.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.03.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.04
-
cpe:2.3:a:intranda:goobi_viewer_core:21.04.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.04.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.04.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.04.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.04.5
-
cpe:2.3:a:intranda:goobi_viewer_core:21.05
-
cpe:2.3:a:intranda:goobi_viewer_core:21.05.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.05.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.5
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.6
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.7
-
cpe:2.3:a:intranda:goobi_viewer_core:21.06.8
-
cpe:2.3:a:intranda:goobi_viewer_core:21.07
-
cpe:2.3:a:intranda:goobi_viewer_core:21.07.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.07.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.5
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.6
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.7
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.8
-
cpe:2.3:a:intranda:goobi_viewer_core:21.08.9
-
cpe:2.3:a:intranda:goobi_viewer_core:21.09
-
cpe:2.3:a:intranda:goobi_viewer_core:21.09.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.09.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.09.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.09.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.10
-
cpe:2.3:a:intranda:goobi_viewer_core:21.10.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.10.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.10.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.10.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.10.5
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11.1
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11.2
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11.3
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11.4
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11.5
-
cpe:2.3:a:intranda:goobi_viewer_core:21.11.6
-
cpe:2.3:a:intranda:goobi_viewer_core:21.12
-
cpe:2.3:a:intranda:goobi_viewer_core:22.01
-
cpe:2.3:a:intranda:goobi_viewer_core:22.01.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.01.2
-
cpe:2.3:a:intranda:goobi_viewer_core:22.01.3
-
cpe:2.3:a:intranda:goobi_viewer_core:22.02
-
cpe:2.3:a:intranda:goobi_viewer_core:22.02.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.02.2
-
cpe:2.3:a:intranda:goobi_viewer_core:22.02.3
-
cpe:2.3:a:intranda:goobi_viewer_core:22.03
-
cpe:2.3:a:intranda:goobi_viewer_core:22.03.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.05
-
cpe:2.3:a:intranda:goobi_viewer_core:22.05.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.06
-
cpe:2.3:a:intranda:goobi_viewer_core:22.06.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.06.2
-
cpe:2.3:a:intranda:goobi_viewer_core:22.06.3
-
cpe:2.3:a:intranda:goobi_viewer_core:22.06.4
-
cpe:2.3:a:intranda:goobi_viewer_core:22.07
-
cpe:2.3:a:intranda:goobi_viewer_core:22.08
-
cpe:2.3:a:intranda:goobi_viewer_core:22.08.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.08.2
-
cpe:2.3:a:intranda:goobi_viewer_core:22.08.3
-
cpe:2.3:a:intranda:goobi_viewer_core:22.08.4
-
cpe:2.3:a:intranda:goobi_viewer_core:22.09
-
cpe:2.3:a:intranda:goobi_viewer_core:22.10
-
cpe:2.3:a:intranda:goobi_viewer_core:22.10.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.10.2
-
cpe:2.3:a:intranda:goobi_viewer_core:22.10.3
-
cpe:2.3:a:intranda:goobi_viewer_core:22.10.4
-
cpe:2.3:a:intranda:goobi_viewer_core:22.10.5
-
cpe:2.3:a:intranda:goobi_viewer_core:22.11
-
cpe:2.3:a:intranda:goobi_viewer_core:22.11.1
-
cpe:2.3:a:intranda:goobi_viewer_core:22.12
-
cpe:2.3:a:intranda:goobi_viewer_core:23.01
-
cpe:2.3:a:intranda:goobi_viewer_core:23.01.1
-
cpe:2.3:a:intranda:goobi_viewer_core:23.01.2
-
cpe:2.3:a:intranda:goobi_viewer_core:23.02
-
cpe:2.3:a:intranda:goobi_viewer_core:3.4.10
-
cpe:2.3:a:intranda:goobi_viewer_core:3.4.2
-
cpe:2.3:a:intranda:goobi_viewer_core:3.4.7
-
cpe:2.3:a:intranda:goobi_viewer_core:3.4.8
-
cpe:2.3:a:intranda:goobi_viewer_core:3.4.9
-
cpe:2.3:a:intranda:goobi_viewer_core:4.10.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.10.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.10.3
-
cpe:2.3:a:intranda:goobi_viewer_core:4.11.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.11.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.12.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.12.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.12.2
-
cpe:2.3:a:intranda:goobi_viewer_core:4.13.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.13.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.2
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.3
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.5
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.6
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.7
-
cpe:2.3:a:intranda:goobi_viewer_core:4.3.8
-
cpe:2.3:a:intranda:goobi_viewer_core:4.4.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.4.2
-
cpe:2.3:a:intranda:goobi_viewer_core:4.5.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.5.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.6.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.6.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.6.2
-
cpe:2.3:a:intranda:goobi_viewer_core:4.7.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.7.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.8.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.8.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.8.2
-
cpe:2.3:a:intranda:goobi_viewer_core:4.8.3
-
cpe:2.3:a:intranda:goobi_viewer_core:4.9.0
-
cpe:2.3:a:intranda:goobi_viewer_core:4.9.1
-
cpe:2.3:a:intranda:goobi_viewer_core:4.9.2