PT-2024-14047 · Qstar · Qstar Archive Solutions

Published

2024-01-13

·

Updated

2024-01-18

·

CVE-2023-51068

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QStar Archive Solutions version RELEASE 3-0 Build 7
Description The issue is related to an authenticated reflected cross-site scripting (XSS) vulnerability. This allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.
Recommendations For QStar Archive Solutions version RELEASE 3-0 Build 7, consider disabling the feature that allows execution of javascript code until a patch is available. Restrict access to the module that handles crafted links to minimize the risk of exploitation. Avoid using the vulnerable link handling functionality in the affected version until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-51068

Affected Products

Qstar Archive Solutions