Cross-Site Scripting Vulnerability in UniFi Network by Ubiquiti
CVE-2023-32000

4.8MEDIUM

Key Information:

Vendor

Ubiquiti

Vendor
CVE Published:
8 July 2023

What is CVE-2023-32000?

A critical Cross-Site Scripting (XSS) vulnerability has been identified in UniFi Network, allowing attackers with Site Administrator credentials to exploit site configurations. By tricking a legitimate Administrator into visiting a specially crafted malicious web page, the attacker can execute harmful scripts in the context of the user's session. This could lead to unauthorized access and manipulation of sensitive data. It is advised that users immediately check their systems and apply patches as outlined in Ubiquiti's Security Advisory.

Affected Version(s)

UniFi Network Application 7.3.83

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.