PT-2023-22644 · Unknown · Neox Contact Center
Huzefa2212
·
Published
2023-06-22
·
Updated
2023-06-29
·
CVE-2023-30347
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Neox Contact Center version 2.3.9
Description
A Cross Site Scripting (XSS) issue exists, allowing exploitation via the
serach sms api name parameter to the SMA API search.Recommendations
For Neox Contact Center version 2.3.9, avoid using the
serach sms api name parameter in the SMA API search until the issue is resolved. As a temporary workaround, consider restricting access to the SMA API to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neox Contact Center