PT-2023-25359 · No Magic · Teamwork Cloud

Johannes Rückert

·

Published

2023-09-13

·

Updated

2023-09-15

·

CVE-2023-3588

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Teamwork Cloud versions No Magic Release 2021x through No Magic Release 2022x
Description A stored Cross-site Scripting (XSS) issue allows an attacker to execute arbitrary script code.
Recommendations For versions No Magic Release 2021x through No Magic Release 2022x, update to a version that is not affected by this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-3588

Affected Products

Teamwork Cloud