Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
CVE-2023-4433
8.3HIGH
What is CVE-2023-4433?
A stored cross-site scripting (XSS) vulnerability exists in the Cockpit Web Console repository prior to version 2.6.4. This flaw allows attackers to inject malicious scripts, which can then be executed in the context of the affected user's browser, potentially compromising sensitive information and enabling unauthorized actions within the application. Proper validation and sanitization measures should be implemented to mitigate such risks.
Affected Version(s)
cockpit-hq/cockpit < 2.6.4
