Persistent XSS Vulnerability in VX Search Enterprise Could Allow Attacker to Store Malicious JavaScript Payloads
CVE-2023-49575
What is CVE-2023-49575?
A persistent cross-site scripting (XSS) vulnerability has been identified in VX Search Enterprise that affects version 10.2.14. The vulnerability involves inadequate input validation on the '/setup_smtp' endpoint, particularly in the parameters: smtp_server, smtp_user, smtp_password, and smtp_email_address. An attacker can exploit this vulnerability to store malicious JavaScript code on the server, which may be executed in the context of users who access the compromised page. This can lead to unauthorized actions being taken on behalf of users and potential exposure of sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Disk Pulse Enterprise 10.4.18
Sync Breeze Enterprise Server 10.4.18
VX Search Enterprise 10.2.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
