Stored Cross-Site Scripting Vulnerability in BlackBerry AtHoc Management Console
CVE-2023-21523

5.4MEDIUM

Key Information:

Vendor

BlackBerry

Status
Vendor
CVE Published:
12 September 2023

What is CVE-2023-21523?

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Management Console of BlackBerry AtHoc, specifically affecting User Management and Alerts features in version 7.15. This security flaw can be exploited by attackers to execute malicious script commands within the context of an affected user’s account, potentially leading to unauthorized actions or data exposure. Users are encouraged to apply necessary updates and security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

AtHoc 7.15

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.