The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."
References
Link | Resource |
---|---|
https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-30394 | Third Party Advisory |
https://github.com/ros-planning/moveit | Product |
https://i.ibb.co/R2JSPV5/2022-10-02-12-39-57-Window.png | Broken Link |
https://i.ibb.co/RyRSzpN/Response-Manipulation.png | Broken Link |
https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-30394 | Third Party Advisory |
https://github.com/ros-planning/moveit | Product |
https://i.ibb.co/R2JSPV5/2022-10-02-12-39-57-Window.png | Broken Link |
https://i.ibb.co/RyRSzpN/Response-Manipulation.png | Broken Link |
Configurations
History
30 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact." |
Information
Published : 2023-05-11 19:15
Updated : 2025-05-30 14:15
NVD link : CVE-2023-30394
Mitre link : CVE-2023-30394
CVE.ORG link : CVE-2023-30394
JSON object : View
Products Affected
moveit
- moveit
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')