CVE-2023-1860: Keysight IXIA Hawkeye licenses cross site scripting
A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. It has been declared as problematic. This vulnerability affects unknown code of the file /licenses. The manipulation of the argument view with the input teste"><script>alert(%27c4ng4c3ir0%27)</script> leads to cross site scripting. The attack can be initiated remotely. VDB-224998 is the identifier assigned to this vulnerability. NOTE: Vendor did not respond if and how they may handle this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1860?
CVE-2023-1860 has been declared as a problematic vulnerability that may allow for cross-site scripting attacks.
How do I fix CVE-2023-1860?
To fix CVE-2023-1860, ensure that you update Keysight IXIA Hawkeye to the latest version or apply any available patches.
What components are affected by CVE-2023-1860?
CVE-2023-1860 affects the /licenses file in Keysight IXIA Hawkeye version 3.3.16.28.
What type of vulnerability is CVE-2023-1860?
CVE-2023-1860 is a cross-site scripting vulnerability that can be exploited through crafted input.
What are the potential impacts of exploiting CVE-2023-1860?
Exploiting CVE-2023-1860 could allow an attacker to execute arbitrary JavaScript in the context of a user's session.