PT-2023-25017 · Unknown · I-Doit Open

·

CVE-2023-34830

·

Published

2023-06-17

·

Updated

2023-07-06

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions i-doit Open version v24
Description A reflected cross-site scripting (XSS) issue was found in i-doit Open via the timeout parameter on the "/login" page. This allows for potential XSS attacks.
Recommendations For i-doit Open version v24, consider disabling access to the login page or restricting the use of the timeout parameter until a fix is available. Avoid using the timeout parameter in the login page until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-34830

Affected Products

I-Doit Open