Medium severity5.4NVD Advisory· Published May 4, 2023· Updated Jun 17, 2026
CVE-2023-30095
CVE-2023-30095
Description
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TotalJS/messengerdescription
Patches
Vulnerability mechanics
References
3- github.com/totaljs/messenger/issues/11nvdExploitIssue TrackingVendor Advisory
- www.edoardoottavianelli.it/CVE-2023-30095/nvdExploitThird Party Advisory
- www.youtube.com/watchnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.