CVE-2023-30394: XSS
Published May 11, 2023
·Updated
Progress Ipswitch MoveIT 1.1.11 was discovered to contain a cross-site scripting (XSS) vulenrability via the API authentication function.
Other sources
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."
— MITRE
Affected Software
1 affected component
MOVEit MoveIT=1.1.11
Event History
May 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-30394?
The severity of CVE-2023-30394 is rated as medium with a CVSS score of 6.1.
2
How can I fix the cross-site scripting vulnerability in Progress Ipswitch MoveIT 1.1.11 (CVE-2023-30394)?
To fix the XSS vulnerability in Progress Ipswitch MoveIT 1.1.11, ensure to sanitize all user input and validate data before displaying it on web pages.