First published: Fri May 26 2023(Updated: )
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware NSX-T Data Center | >=3.2.0<3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20868 is a reflected cross-site scripting vulnerability in NSX-T due to a lack of input validation, allowing remote attackers to inject HTML or JavaScript to redirect to malicious pages.
CVE-2023-20868 affects NSX-T Data Center versions between 3.2.0 and 3.2.3.
CVE-2023-20868 has a severity level of medium with a CVSS score of 6.1.
A remote attacker can exploit CVE-2023-20868 by injecting HTML or JavaScript code to redirect victims to malicious websites.
Yes, VMware has released a security advisory (VMSA-2023-0010) that provides patches and remediation steps to address the vulnerability.