A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-54445 A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.
Fixes

Solution

There is no reported solution at this time.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-05T13:58:49.858Z

Reserved: 2023-08-29T08:19:30.797Z

Link: CVE-2023-4592

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.533Z

cve-icon NVD

Status : Modified

Published: 2023-11-03T12:15:08.873

Modified: 2024-11-21T08:35:30.163

Link: CVE-2023-4592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses