CVE-2023-1789 MEDIUM

CVE-2023-1789: Improper Input Validation in firefly-iii/firefly-iii

Vendor Firefly-Iii
Product firefly-iii/firefly-iii
Weakness CWE-20 · Input validation
Published April 1, 2023
Last update February 11, 2025

CVSS base score

5.2/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.

Key dates

02Disclosure timeline

April 1, 2023 CVE published
February 11, 2025 Record updated