Stored Cross-Site Scripting in VI Web Client by Vendor
CVE-2023-40705
5.4MEDIUM
What is CVE-2023-40705?
A stored cross-site scripting vulnerability exists in the Map setting page of the VI Web Client, allowing remote authenticated attackers to inject arbitrary scripts. Successful exploitation can lead to session hijacking or unauthorized actions performed by users, compromising sensitive information and the integrity of the application. Users are encouraged to update to version 7.9.6 or later to mitigate this risk.
Affected Version(s)
VI Web Client prior to 7.9.6
