CVE-2023-20868: XSS
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20868?
CVE-2023-20868 is a reflected cross-site scripting vulnerability in NSX-T due to a lack of input validation, allowing remote attackers to inject HTML or JavaScript to redirect to malicious pages.
How does CVE-2023-20868 affect NSX-T Data Center?
CVE-2023-20868 affects NSX-T Data Center versions between 3.2.0 and 3.2.3.
What is the severity of CVE-2023-20868?
CVE-2023-20868 has a severity level of medium with a CVSS score of 6.1.
How can a remote attacker exploit CVE-2023-20868?
A remote attacker can exploit CVE-2023-20868 by injecting HTML or JavaScript code to redirect victims to malicious websites.
Is there a fix available for CVE-2023-20868?
Yes, VMware has released a security advisory (VMSA-2023-0010) that provides patches and remediation steps to address the vulnerability.