PT-2023-22363 · Gbcom · Gbcom Lac Web Control Center

Shellpei

·

Published

2023-06-22

·

Updated

2023-06-30

·

CVE-2023-29707

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GBCOM LAC WEB Control Center version lac-1.3.x
Description The issue allows attackers to create an arbitrary device through a Cross Site Scripting (XSS) vulnerability.
Recommendations For GBCOM LAC WEB Control Center version lac-1.3.x, consider disabling the functionality that allows device creation until a patch is available. Restrict access to the control center to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-29707

Affected Products

Gbcom Lac Web Control Center