CVE-2023-2044: Control iD iDSecure Dispositivos Page cross site scripting
A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown code of the component Dispositivos Page. The manipulation of the argument IP-DNS leads to cross site scripting. The attack can be initiated remotely. VDB-225922 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2044?
The severity of CVE-2023-2044 is medium (6.1).
How does CVE-2023-2044 affect Control iD iDSecure?
CVE-2023-2044 affects Control iD iDSecure version 4.7.29.1.
What is the CWE category of CVE-2023-2044?
The CWE category of CVE-2023-2044 is CWE-79 (Cross-Site Scripting).
Can CVE-2023-2044 be initiated remotely?
Yes, the attack can be initiated remotely for CVE-2023-2044.
How can I fix CVE-2023-2044?
To fix CVE-2023-2044, update Control iD iDSecure to a version that addresses the vulnerability.