PT-2023-25017 · Unknown · I-Doit Open
Leekenghwa
·
Published
2023-06-17
·
Updated
2023-07-06
·
CVE-2023-34830
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
i-doit Open version v24
Description
A reflected cross-site scripting (XSS) issue was found in i-doit Open via the
timeout parameter on the "/login" page. This allows for potential XSS attacks.Recommendations
For i-doit Open version v24, consider disabling access to the login page or restricting the use of the
timeout parameter until a fix is available. Avoid using the timeout parameter in the login page until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
I-Doit Open