Reflected Cross-Site Scripting Vulnerability in NSX-T by VMware
CVE-2023-20868

6.1MEDIUM

Key Information:

Vendor

Vmware

Status
Vendor
CVE Published:
26 May 2023

What is CVE-2023-20868?

VMware NSX-T contains a reflected cross-site scripting vulnerability caused by inadequate input validation. This allows a remote attacker to exploit the flaw by injecting malicious HTML or JavaScript code, potentially leading to redirection to harmful websites. Organizations should ensure that they apply the necessary security patches to protect against this vulnerability.

Affected Version(s)

NSX-T NSX-T 3.2.x VCF 4.5.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.