PT-2023-22536 · Unknown · Totaljs Flow
Edoardottt
·
Published
2023-05-04
·
Updated
2023-05-11
·
CVE-2023-30094
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TotalJS Flow version 10
Description
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the
platform name field in the settings module. This issue enables attackers to inject malicious code, potentially leading to unauthorized access or control of the affected system.Recommendations
For TotalJS Flow version 10, consider disabling the settings module or restricting access to it until a patch is available. Avoid using the
platform name field in the settings module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totaljs Flow