CVE-2023-32193 - CERT CVE
ID CVE-2023-32193
Sažetak A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.
Reference
CVSS
Base: 8.3
Impact: 5.5
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Zadnje važnije ažuriranje 16-10-2024 - 16:38
Objavljeno 16-10-2024 - 13:15