A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-03-10T00:00:00

Updated: 2024-08-02T10:28:40.690Z

Reserved: 2023-01-11T00:00:00

Link: CVE-2023-23326

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-03-10T22:15:10.277

Modified: 2023-03-16T15:56:41.620

Link: CVE-2023-23326

cve-icon Redhat

No data.