PT-2024-13392 · Temenos · Temenos T24 Browser
Azraelsblade
·
Published
2024-09-23
·
Updated
2024-09-26
·
CVE-2023-46948
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Temenos T24 Browser version R19.40
Description
A reflected Cross-Site Scripting (XSS) issue was discovered, allowing a remote attacker to execute arbitrary JavaScript code. This is achieved via the
skin parameter in the "about.jsp" and "genrequest.jsp" components.Recommendations
For Temenos T24 Browser version R19.40, consider restricting access to the
about.jsp and genrequest.jsp components until a patch is available. As a temporary workaround, avoid using the skin parameter in these components to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Temenos T24 Browser