PT-2024-13251 · Veridium · Veridiumid
Lim Jing Qiang
·
Published
2024-04-03
·
Updated
2024-04-03
·
CVE-2023-45552
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
VeridiumID versions prior to 3.5.0
Description
A stored cross-site scripting issue has been found in the admin portal of the affected software. This allows an authenticated attacker to potentially take over all accounts by sending malicious input via the self-service portal.
Recommendations
For versions prior to 3.5.0, update to version 3.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin portal and self-service portal to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veridiumid