Medium severity5.4NVD Advisory· Published Feb 17, 2023· Updated Jun 17, 2026
CVE-2023-24769
CVE-2023-24769
Description
Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter under the "Add a new change detection watch" function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
changedetection.ioPyPI | < 0.40.2 | 0.40.2 |
Affected products
3- cpe:2.3:a:webtechnologies:changedetection:*:*:*:*:*:*:*:*Range: <0.40.1.1
Patches
Vulnerability mechanics
References
7- github.com/dgtlmoon/changedetection.io/issues/1358nvdExploitVendor AdvisoryWEB
- www.youtube.com/watchnvdExploitWEB
- github.com/advisories/GHSA-68wj-c2jw-5pp9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-24769ghsaADVISORY
- github.com/dgtlmoon/changedetection.io/pull/1359ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/changedetection-io/PYSEC-2023-10.yamlghsaWEB
- www.edoardoottavianelli.it/CVE-2023-24769nvdWEB
News mentions
0No linked articles in our index yet.