A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-03-10T00:00:00

Updated: 2023-03-10T00:00:00

Reserved: 2023-01-11T00:00:00


Link: CVE-2023-23326

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-03-10T22:15:10.277

Modified: 2023-03-16T15:56:41.620


Link: CVE-2023-23326

JSON object: View

cve-icon Redhat Information

No data.

CWE