Description
The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious web script into its name, that will execute whenever a user accesses the search page.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49763 | The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious web script into its name, that will execute whenever a user accesses the search page. |
References
| Link | Providers |
|---|---|
| https://github.com/itsAptx/CVE-2023-45471 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-12T14:46:00.549Z
Reserved: 2023-10-09T00:00:00.000Z
Link: CVE-2023-45471
Updated: 2024-08-02T20:21:16.206Z
Status : Modified
Published: 2023-10-20T04:15:10.720
Modified: 2024-11-21T08:26:54.647
Link: CVE-2023-45471
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD