Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability
CVE-2023-27335
9.6CRITICAL
What is CVE-2023-27335?
A Cross-Site Scripting vulnerability found in the Softing edgeAggregator client enables remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious web page or opening a compromised file. The vulnerability arises from inadequate validation of user input handling which permits the injection of malicious scripts. Attackers can exploit this issue alongside other vulnerabilities to execute arbitrary code with elevated privileges. This poses a significant risk to the security and integrity of systems utilizing the edgeAggregator client.
Affected Version(s)
edgeAggregator 3.40
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
