Reflected XSS Vulnerability in BlackBerry AtHoc Management Console
CVE-2023-21522

6.1MEDIUM

Key Information:

Vendor

BlackBerry

Status
Vendor
CVE Published:
12 September 2023

What is CVE-2023-21522?

A reflected cross-site scripting (XSS) vulnerability exists within the Management Console Reports of BlackBerry AtHoc, specifically in version 7.15. This security flaw could enable an attacker to inject malicious scripts into the console, potentially allowing unauthorized commands to be executed in the context of the affected user's browser session. The exploit poses a significant security risk, as it may facilitate access to sensitive information and unauthorized actions performed on behalf of the user.

Affected Version(s)

AtHoc 7.15

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.