PT-2023-27603 · Unknown · Vi Web Client

Michael Heinzl

·

Published

2023-09-05

·

Updated

2023-09-08

·

CVE-2023-40705

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VI Web Client versions prior to 7.9.6
Description A stored cross-site scripting issue in the Map setting page allows a remote authenticated attacker to inject an arbitrary script.
Recommendations For versions prior to 7.9.6, update to version 7.9.6 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-40705

Affected Products

Vi Web Client