Stored Cross-Site Scripting in VI Web Client by Vendor
CVE-2023-40705

5.4MEDIUM

Key Information:

Vendor
CVE Published:
5 September 2023

What is CVE-2023-40705?

A stored cross-site scripting vulnerability exists in the Map setting page of the VI Web Client, allowing remote authenticated attackers to inject arbitrary scripts. Successful exploitation can lead to session hijacking or unauthorized actions performed by users, compromising sensitive information and the integrity of the application. Users are encouraged to update to version 7.9.6 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

VI Web Client prior to 7.9.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.