Medium severity5.4NVD Advisory· Published Mar 14, 2023· Updated Jun 17, 2026
CVE-2023-27070
CVE-2023-27070
Description
A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TotalJS/OpenPlatformdescription
(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:totaljs:openplatform:2023-02-16:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
3- github.com/totaljs/openplatform/issues/53nvdExploitIssue Tracking
- www.youtube.com/watchnvdExploit
- www.edoardoottavianelli.it/CVE-2023-27070/nvd
News mentions
0No linked articles in our index yet.