CVE-2023-26608: XSS
Published Mar 1, 2023
·Updated
SOLDR (System of Orchestration, Lifecycle control, Detection and Response) 1.1.0 allows stored XSS via the module editor.
Affected Software
1 affected component
Vxcontrol Soldr=1.1.0
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-26608?
CVE-2023-26608 has a moderate severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2023-26608?
To fix CVE-2023-26608, upgrade to version 1.2.0 of the SOLDR software, which addresses the vulnerability.
3
What types of attacks can be performed using CVE-2023-26608?
CVE-2023-26608 can be exploited to execute stored XSS attacks, allowing attackers to inject malicious scripts into the application.
4
Which versions of SOLDR are affected by CVE-2023-26608?
CVE-2023-26608 affects SOLDR version 1.1.0 and earlier versions.
5
Is any user data at risk because of CVE-2023-26608?
Yes, user data can be at risk due to the possibility of an attacker executing scripts that steal session cookies or manipulate user actions.