A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14 that could allow an attacker to execute persistent XSS through /add_job in job_name. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Mar 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Flexense
Flexense vx Search
CPEs cpe:2.3:a:flexense:vx_search:10.2.14:*:*:*:enterprise:*:*:*
Vendors & Products Flexense
Flexense vx Search

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-02T22:01:24.745Z

Reserved: 2023-11-27T15:14:26.602Z

Link: CVE-2023-49574

cve-icon Vulnrichment

Updated: 2024-08-02T22:01:24.745Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-24T13:15:09.023

Modified: 2025-03-04T17:00:22.900

Link: CVE-2023-49574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.