Description
This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter within the admin panel.
Published: 2023-10-03
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Canopsis version 23.10.0 includes fixes for the reported vulnerability, and was released on 31 October 2023.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54419 This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter within the admin panel.
History

Tue, 01 Oct 2024 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 11:00:00 +0000


Subscriptions

Capensis Canopsis
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-10-01T10:45:55.688Z

Reserved: 2023-08-28T11:12:19.891Z

Link: CVE-2023-4564

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.603Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T16:15:10.227

Modified: 2024-11-21T08:35:26.163

Link: CVE-2023-4564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses