PT-2023-25707 · 2Fa · 2Fa
Quirinziessler
·
Published
2023-07-03
·
Updated
2023-07-10
·
CVE-2023-36816
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
2FA versions prior to 4.0.3
Description
The issue is related to a Cross Site Scripting (XSS) injection vulnerability in the 2FA Web application, which manages Two-Factor Authentication accounts and generates security codes. The XSS injection can be done via the
account/service field. This vulnerability was tested in a docker-compose environment.Recommendations
For versions prior to 4.0.3, update to version 4.0.3 to resolve the issue. As a temporary workaround, consider restricting access to the
account/service field to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
2Fa