This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter within the admin panel.
Fixes

Solution

Canopsis version 23.10.0 includes fixes for the reported vulnerability, and was released on 31 October 2023.


Workaround

No workaround given by the vendor.

History

Tue, 01 Oct 2024 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 11:00:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-10-01T10:45:55.688Z

Reserved: 2023-08-28T11:12:19.891Z

Link: CVE-2023-4564

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.603Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T16:15:10.227

Modified: 2024-11-21T08:35:26.163

Link: CVE-2023-4564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.