PT-2023-19677 · Unknown · Crm Bsp Frame
Published
2023-02-14
·
Updated
2023-04-12
·
CVE-2023-24529
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BSP application (CRM BSP FRAME) versions 700 through 75H
Description
The issue is due to a lack of proper input validation, allowing malicious inputs from untrusted sources. This can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack, potentially hijacking a user session, reading, and modifying sensitive information.
Recommendations
For versions 700 through 75H, as a temporary workaround, consider implementing proper input validation to prevent malicious inputs from untrusted sources. Restrict access to sensitive information and user sessions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crm Bsp Frame