PT-2024-12961 · Softwarex · Softwarex

Published

2024-02-12

·

Updated

2024-10-17

·

CVE-2023-41703

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SoftwareX (affected versions not specified)
Description The issue arises from the improper sanitization of User ID references at mentions in document comments, allowing script code to be injected into a user's session when working with a malicious document. This could potentially lead to malicious content being executed. However, no publicly available exploits are known. User-defined content, such as comments and mentions, is now filtered to avoid potentially malicious content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-41703

Affected Products

Softwarex