Cross-Site Scripting Vulnerability in Optimizely CMS Admin Panel
CVE-2023-31754

4.8MEDIUM

Key Information:

Vendor

Optimizely

Vendor
CVE Published:
14 November 2023

What is CVE-2023-31754?

A vulnerability in the Optimizely CMS before version 12.16.0 allows for cross-site scripting attacks through the Admin panel. Attackers can exploit this weakness to inject malicious scripts into web pages that are viewed by administrative users. This can lead to unauthorized data access and potential compromise of the affected system, emphasizing the need for timely updates and monitoring of security protocols.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.