A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session.
References
Link | Resource |
---|---|
http://avantfax.com | Vendor Advisory |
https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md | Exploit Third Party Advisory |
Configurations
History
16 Mar 2023, 15:56
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md - Exploit, Third Party Advisory | |
References | (MISC) http://avantfax.com - Vendor Advisory | |
CPE | cpe:2.3:a:avantfax:avantfax:3.3.7:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CWE | CWE-79 |
11 Mar 2023, 02:54
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-10 22:15
Updated : 2024-02-04 23:14
NVD link : CVE-2023-23326
Mitre link : CVE-2023-23326
CVE.ORG link : CVE-2023-23326
JSON object : View
Products Affected
avantfax
- avantfax
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')