PT-2025-1476 · Unknown · Selesta Visual Access Manager
Published
2025-01-13
·
Updated
2025-01-14
·
CVE-2023-42250
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
The software that is vulnerable is Selesta Visual Access Manager, specifically versions less than 4.42.2.
The vulnerability is a Cross Site Scripting (XSS) vulnerability that can be exploited via the /common/autocomplete.php file.
This vulnerability has been assigned the CVE identifier CVE-2023-42250.
There is a public reference to this vulnerability available at the provided URLs, which may indicate the existence of a public exploit.
However, there is no information provided about whether this vulnerability has been actively exploited by attackers or the potential number of internet users that could be affected.
The vulnerability can be exploited by sending malicious input to the /common/autocomplete.php file, potentially allowing an attacker to inject and execute arbitrary JavaScript code in a user's browser.
#SelestaVisualAccessManager #CrossSiteScripting #XSS #CVE202342250 #Vulnerability #Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Selesta Visual Access Manager