CVE-2023-22373: XSS
Published Jan 20, 2023
·Updated
Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.
Affected Software
2 affected components
Contec CONPROSYS HMI System<=3.4.5
Contec CONPROSYS HMI System (CHS): Ver.3.4.4 and prior
Remediation
Patch Available
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22373.
2
What is the severity of CVE-2023-22373?
The severity of CVE-2023-22373 is medium (5.4).
3
What is affected by CVE-2023-22373?
CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier is affected by CVE-2023-22373.
4
How does CVE-2023-22373 exploit work?
CVE-2023-22373 allows a remote authenticated attacker to inject an arbitrary script and obtain sensitive information.
5
How can I fix CVE-2023-22373?
Update CONPROSYS HMI System to a version later than 3.4.5 to fix CVE-2023-22373.