First published: Mon May 01 2023(Updated: )
Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Archer | >=6.8.0.0<=6.11.0.4 | |
RSA Archer | >=6.12.0.0<6.12.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Archer Platform is CVE-2023-30639.
The severity of CVE-2023-30639 is high with a CVSS score of 5.4.
CVE-2023-30639 is a stored XSS vulnerability that allows a remote authenticated malicious user to store malicious HTML or JavaScript code in a trusted application data store.
Archer Platform versions between 6.8.0.0 and 6.11.0.4, as well as versions between 6.12.0.0 and 6.12.0.6.1, are affected by CVE-2023-30639.
To fix CVE-2023-30639, upgrade Archer Platform to version 6.12 P6 HF1 (6.12.0.6.1) or later.