Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tags directly using the content of the queried URL, which would allow an attacker to inject HTML/Javascript code into the response.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-widestand-cms-acilia | Third Party Advisory |
https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-widestand-cms-acilia | Third Party Advisory |
Configurations
History
21 Nov 2024, 08:34
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-04 12:15
Updated : 2024-11-21 08:34
NVD link : CVE-2023-4090
Mitre link : CVE-2023-4090
CVE.ORG link : CVE-2023-4090
JSON object : View
Products Affected
acilia
- widestand
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')