Description
This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page description parameters within the administration panel.
Published: 2023-10-03
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Canopsis version 23.10.0 includes fixes for the reported vulnerability, and was released on 31 October 2023.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-43874 This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page description parameters within the administration panel.
History

Tue, 01 Oct 2024 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 11:00:00 +0000


Subscriptions

Capensis Canopsis
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-10-01T10:43:49.865Z

Reserved: 2023-06-12T11:42:38.992Z

Link: CVE-2023-3196

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:08.281Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T16:15:10.077

Modified: 2024-11-21T08:16:40.297

Link: CVE-2023-3196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses