Cross-Site Scripting Vulnerability in Pexip Infinity Web Application
CVE-2023-37225

6.1MEDIUM

Key Information:

Vendor

Pexip

Vendor
CVE Published:
25 December 2023

What is CVE-2023-37225?

A vulnerability has been identified in Pexip Infinity versions prior to 32, allowing attackers to exploit the Webapp1 component through preconfigured links. This flaw opens up potential avenues for XSS attacks, enabling unauthorized actions to be performed in the context of affected user sessions. Users of Pexip Infinity are advised to review their configurations and apply the recommended updates to mitigate potential risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-37225 : Cross-Site Scripting Vulnerability in Pexip Infinity Web Application