{"id":"CVE-2023-45957","details":"A stored cross-site scripting (XSS) vulnerability in the component admin/AdminRequestSqlController.php of thirty bees before 1.5.0 allows attackers to execute arbitrary web script or HTML via $e-\u003egetMessage() error mishandling.","modified":"2026-04-12T07:21:08.093529Z","published":"2023-12-22T16:15:08.327Z","references":[{"type":"ADVISORY","url":"https://github.com/thirtybees/thirtybees/compare/1.4.0...1.5.0"},{"type":"ADVISORY","url":"https://zigrin.com/advisories/thirty-bees-stored-cross-site-scripting-xss/"},{"type":"FIX","url":"https://github.com/thirtybees/thirtybees/commit/f5b2c1e0094ce53fded1443bab99a604ae8e2968"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thirtybees/thirtybees","events":[{"introduced":"0"},{"fixed":"d1ce11dc68ac7da6008c27e2d716dfe80b47e0b4"},{"fixed":"f5b2c1e0094ce53fded1443bab99a604ae8e2968"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.5.0"}],"source":["CPE_FIELD","REFERENCES"],"cpe":"cpe:2.3:a:thirtybees:thirty_bees:*:*:*:*:*:*:*:*"}}],"versions":["1.0.0","1.0.0-beta3","1.0.1","1.0.2","1.0.2-beta.1","1.0.3","1.0.4","1.0.4-rc.1","1.0.5","1.0.6","1.0.7","1.0.8","1.1.0","1.2.0","1.3.0","1.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-45957.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}