PT-2023-5296 · Unknown · Mod3Gp-Sy-120K

·

CVE-2023-38582

·

Publicado

2023-09-07

·

Atualizado

2024-08-02

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MOD3GP-SY-120K (affected versions not specified)
Description The web application of MOD3GP-SY-120K contains a persistent cross-site scripting (XSS) issue. This allows an authenticated remote attacker to inject an XSS payload into the MAIL RCV field, which will be executed when a legitimate user accesses the vulnerable page. The issue arises due to inadequate protection of the web page structure, enabling remote attackers to perform XSS attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05922
CVE-2023-38582

Produtos afetados

Mod3Gp-Sy-120K