Unknown · Bill-Ahmed Qbit-Matui · CVE-2023-50473
**Name of the Vulnerable Software and Affected Versions**
bill-ahmed qbit-matUI version 1.16.4
**Description**
The issue is a Cross-Site Scripting (XSS) vulnerability that allows remote attackers to obtain sensitive information via fixed session identifiers (SID) in the index.js file. This vulnerability enables attackers to exploit the fixed session identifiers to gain access to sensitive information.
**Recommendations**
For bill-ahmed qbit-matUI version 1.16.4, consider updating to a newer version that addresses the Cross-Site Scripting (XSS) vulnerability, or as a temporary workaround, restrict access to the index.js file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.