CVE-2023-30394
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/05/2023
Last modified:
30/05/2025
Description
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:moveit:moveit:1.1.11:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-30394
- https://github.com/ros-planning/moveit
- https://i.ibb.co/R2JSPV5/2022-10-02-12-39-57-Window.png
- https://i.ibb.co/RyRSzpN/Response-Manipulation.png
- https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-30394
- https://github.com/ros-planning/moveit
- https://i.ibb.co/R2JSPV5/2022-10-02-12-39-57-Window.png
- https://i.ibb.co/RyRSzpN/Response-Manipulation.png



