Gestsup XSS Vulnerability Allows Arbitrary Script Execution
CVE-2023-52059

5.4MEDIUM

Key Information:

Vendor

Gestsup

Status
Vendor
CVE Published:
13 February 2024

What is CVE-2023-52059?

A vulnerability in Gestsup version 3.2.46 allows attackers to perform cross-site scripting (XSS) attacks. This weakness occurs due to improper validation of user input within the Description text field. By injecting malicious web scripts or HTML payloads, an attacker can exploit this vulnerability to execute arbitrary scripts in the context of users' browsers, potentially leading to unauthorized access to sensitive information, session hijacking, or further exploitation of the application. Users of Gestsup are advised to apply available patches and implement appropriate security measures to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.