The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-05 Patch Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-12-07T18:08:04.324Z

Updated: 2023-12-07T18:08:04.324Z

Reserved: 2023-11-27T16:35:14.892Z


Link: CVE-2023-6333

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-07T18:15:08.493

Modified: 2023-12-12T20:39:57.697


Link: CVE-2023-6333

JSON object: View

cve-icon Redhat Information

No data.

CWE