PT-2024-11525 · Ysoft · Y Soft Safeq
Marian-Razvan Ilisanu
·
Published
2024-10-22
·
Updated
2024-11-01
·
CVE-2022-23861
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Y Soft SAFEQ version 6 Build 53
Description
Multiple Stored Cross-Site Scripting issues were discovered in the YSoft SafeQ web application. The lack of output sanitization in multiple fields allows for the injection of malicious inputs, resulting in the execution of arbitrary JS code. These fields can be used to perform XSS attacks on legitimate users accessing the SafeQ web interface.
Recommendations
For Y Soft SAFEQ version 6 Build 53, consider disabling the web application's fields that allow user input until a patch is available to prevent the injection of malicious code. Restrict access to the SafeQ web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Y Soft Safeq