PT-2023-22644 · Unknown · Neox Contact Center

Huzefa2212

·

Published

2023-06-22

·

Updated

2023-06-29

·

CVE-2023-30347

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Neox Contact Center version 2.3.9
Description A Cross Site Scripting (XSS) issue exists, allowing exploitation via the serach sms api name parameter to the SMA API search.
Recommendations For Neox Contact Center version 2.3.9, avoid using the serach sms api name parameter in the SMA API search until the issue is resolved. As a temporary workaround, consider restricting access to the SMA API to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-30347

Affected Products

Neox Contact Center