Cross-Site Scripting Vulnerability in Faronics Insight for Windows
CVE-2023-28350

6.1MEDIUM

Key Information:

Vendor

Faronics

Status
Vendor
CVE Published:
31 May 2023

What is CVE-2023-28350?

A vulnerability in Faronics Insight version 10.0.19045 on Windows allows attackers to exploit unsanitized input in both Teacher and Student Console applications. This can lead to the execution of malicious JavaScript, granting attackers control over connected student machines and potentially the teacher's machine. The exploitation of this flaw can have severe implications due to the extensive privileges provided by the Teacher Console.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.