CVE-2023-2421: Control iD RHiD department cross site scripting
Published Apr 29, 2023
·Updated
A vulnerability classified as problematic has been found in Control iD RHiD 23.3.19.0. Affected is an unknown function of the file /v2/#/add/department. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-227718 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
Controlid Rhid=23.3.19.0
Event History
Apr 29, 2023
CVE Published
01:31 AM
Data Sourced
01:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2421.
2
What is the severity of CVE-2023-2421?
The severity of CVE-2023-2421 is medium with a severity value of 6.1.
3
What is the affected software of CVE-2023-2421?
The affected software of CVE-2023-2421 is Control iD RHiD version 23.3.19.0.
4
What is the CWE number for CVE-2023-2421?
The CWE number for CVE-2023-2421 is 79.
5
How can I fix CVE-2023-2421?
To fix CVE-2023-2421, apply the latest security patches or updates provided by Control iD.