What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net bunnycdn allows Stored XSS.This issue affects bunny.net: from n/a through <= 2.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net bunnycdn allows Stored XSS.This issue affects bunny.net: from n/a through <= 2.3.0.
Explanation of Vulnerability in Simple Terms
Bunny.net versions up to 2.3.0 contain a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts affecting other users and the site's availability. An attacker with low-level account access can craft requests that execute JavaScript in victims' browsers and degrade service. The vulnerability has scope impact, meaning the attack can affect resources beyond the vulnerable component itself.
What an attacker can do
Inject and execute JavaScript in other users' browsers; degrade site availability.
Potential impact on your site
Users' sessions and data may be compromised; site performance may degrade due to malicious script execution.
Conditions required to exploit
Attacker must have a low-privilege account on the Bunny.net service.
Key dates
External resources
Related vulnerabilities