This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page description parameters within the administration panel.
Fixes

Solution

Canopsis version 23.10.0 includes fixes for the reported vulnerability, and was released on 31 October 2023.


Workaround

No workaround given by the vendor.

History

Tue, 01 Oct 2024 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 11:00:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-10-01T10:43:49.865Z

Reserved: 2023-06-12T11:42:38.992Z

Link: CVE-2023-3196

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:08.281Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T16:15:10.077

Modified: 2024-11-21T08:16:40.297

Link: CVE-2023-3196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.