Medium severity5.4NVD Advisory· Published May 4, 2023· Updated Jun 17, 2026
CVE-2023-30094
CVE-2023-30094
Description
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
total4npm | < 0.0.81 | 0.0.81 |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/totaljs/flow/issues/100nvdExploitIssue TrackingVendor AdvisoryWEB
- www.edoardoottavianelli.it/CVE-2023-30094/nvdExploitThird Party Advisory
- www.youtube.com/watchnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jj45-24rw-v6jwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-30094ghsaADVISORY
- github.com/totaljs/framework4/commit/e2cea690c3fe4453e94da896a69f832511f65179ghsaWEB
- www.edoardoottavianelli.it/CVE-2023-30094ghsaWEB
- www.youtube.com/watchghsaWEB
News mentions
0No linked articles in our index yet.