VYPR
Moderate severityNVD Advisory· Published Sep 28, 2018· Updated Aug 5, 2024

CVE-2018-17574

CVE-2018-17574

Description

YApi 1.3.23 suffers from stored XSS in the project name field, allowing arbitrary JavaScript execution when users view project dynamics.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

YApi 1.3.23 suffers from stored XSS in the project name field, allowing arbitrary JavaScript execution when users view project dynamics.

Vulnerability

YApi version 1.3.23 (and possibly earlier) contains a stored cross-site scripting (XSS) vulnerability in the project name field. The application does not sanitize user input when creating or editing a project, allowing an attacker to inject arbitrary HTML/JavaScript. This affects the name parameter during project creation [1][4].

Exploitation

An attacker must have a registered account on the YApi instance. They create a new project and set the project name to a malicious payload such as xss">. The project must be made public or added to a public group so that other users (including managers and administrators) can view it. When any user views the operation dynamics of that project, the injected script executes in their browser [4].

Impact

Successful exploitation leads to stored XSS, enabling the attacker to execute arbitrary JavaScript in the context of the victim's session. This can result in theft of session cookies, defacement, or other malicious actions performed on behalf of the victim. The impact is limited to the browser session of users who view the project dynamics [2][4].

Mitigation

The vulnerability was fixed in YApi version 1.3.24 (or later). Users should upgrade to the latest version. The GitHub advisory [3] indicates that versions before 1.3.23 are affected. No workaround is documented; upgrading is the recommended action. The CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
yapi-vendornpm
< 1.3.231.3.23

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.