Description
A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54445 | A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-05T13:58:49.858Z
Reserved: 2023-08-29T08:19:30.797Z
Link: CVE-2023-4592
Updated: 2024-08-02T07:31:06.533Z
Status : Modified
Published: 2023-11-03T12:15:08.873
Modified: 2024-11-21T08:35:30.163
Link: CVE-2023-4592
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD