{"id":"CVE-2023-3521","summary":"Cross-site Scripting (XSS) - Reflected in fossbilling/fossbilling","details":"Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.","modified":"2026-08-12T03:51:21.151405401Z","published":"2023-07-06T01:45:39.229Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3521.json","cna_assigner":"@huntrdev","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/76a3441d-7f75-4a8d-a7a0-95a7f5456eb0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3521.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3521"},{"type":"FIX","url":"https://github.com/fossbilling/fossbilling/commit/5eb516d4ebcb764db1b2edf9c8d0539e76ebde52"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fossbilling/fossbilling","events":[{"introduced":"0"},{"fixed":"df136232c5068efbeb7c1e45e0d87570a4d3d475"},{"fixed":"5eb516d4ebcb764db1b2edf9c8d0539e76ebde52"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:fossbilling:fossbilling:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.5.4"}]}}],"versions":["0.5.3","0.5.2","0.5.1","0.5.0","0.4.3","0.4.2","0.4.1","0.4.0","0.3.0","0.2.10","0.2.9","0.2.8","0.2.7","0.2.6","0.2.5","0.2.4","0.2.3","0.2.2","0.2.1","0.2.0","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3521.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}