Medium severity4.8NVD Advisory· Published Mar 6, 2023· Updated Jun 17, 2026
CVE-2023-1197
CVE-2023-1197
Description
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
uvdesk/community-skeletonPackagist | < 1.1.0 | 1.1.0 |
Affected products
3cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*range: <1.1.0
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/uvdesk/community-skeleton/commit/6fae9442361c8a216611d3622bec26249a8c48a0nvdPatchWEB
- huntr.dev/bounties/97d226ea-2cd8-4f4d-9360-aa46c37fdd26nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hfxp-j95j-cwrpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-1197ghsaADVISORY
- uvdesk/community-skeletonghsaPACKAGE
News mentions
0No linked articles in our index yet.