CVE-2023-22778: Authenticated Stored Cross-Site Scripting
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22778?
CVE-2023-22778 is a vulnerability in the ArubaOS web management interface that allows an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
What is the severity of CVE-2023-22778?
The severity of CVE-2023-22778 is medium with a CVSS score of 4.8.
Which software is affected by CVE-2023-22778?
The affected software includes Arubanetworks SD-WAN, Arubanetworks ArubaOS versions 8.6.0.0 to 8.6.0.19, Arubanetworks ArubaOS versions 8.10.0.0 to 8.10.0.4, and Arubanetworks ArubaOS versions 10.3.0.0 to 10.3.1.0.
How can an attacker exploit CVE-2023-22778?
An attacker can exploit CVE-2023-22778 by injecting malicious script code into the web management interface and executing it in a victim's browser.
Is there a fix for CVE-2023-22778?
Yes, Aruba Networks has released a security advisory with mitigation steps to address CVE-2023-22778. Please refer to the provided reference link for more information.