Cross-site Scripting (XSS) reflected vulnerability on WideStand until 5.3.5 version, which generates one of the meta tags directly using the content of the queried URL, which would allow an attacker to inject HTML/Javascript code into the response.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-widestand-cms-acilia | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-10-04T11:02:48.227Z
Updated: 2023-10-04T11:02:48.227Z
Reserved: 2023-08-02T07:38:03.977Z
Link: CVE-2023-4090
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-04T12:15:10.800
Modified: 2023-10-05T18:12:19.200
Link: CVE-2023-4090
JSON object: View
Redhat Information
No data.
CWE