PT-2023-23938 · Subnet · Subnet Powersystem Center

Published

2023-06-19

·

Updated

2023-06-29

·

CVE-2023-32659

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions SUBNET PowerSYSTEM Center versions 2020 U10 and prior
Description The issue allows an attacker to inject malicious code into report header graphic files, which could propagate out of the system and reach users who are subscribed to email notifications. This is a cross-site scripting vulnerability.
Recommendations For SUBNET PowerSYSTEM Center versions 2020 U10 and prior, update to a version later than 2020 U10 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-32659

Affected Products

Subnet Powersystem Center