PT-2023-25945 · Atarim · Atarim Plugin+1

Robert Devore

·

Published

2023-09-04

·

Updated

2023-09-06

·

CVE-2023-37393

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin versions <= 3.9.3
Description The issue is related to an Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability. This means that an attacker with administrative access can inject malicious scripts into the website, potentially affecting other users. The vulnerability is present in the Atarim plugin for website collaboration, feedback, and project management.
Recommendations For Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin versions <= 3.9.3, update to a version higher than 3.9.3 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-37393

Affected Products

Atarim Visual Website Collaboration
Atarim Plugin