CVE-2023-30639: XSS
Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Archer Platform?
The vulnerability ID for Archer Platform is CVE-2023-30639.
What is the severity of CVE-2023-30639?
The severity of CVE-2023-30639 is high with a CVSS score of 5.4.
How does CVE-2023-30639 impact Archer Platform?
CVE-2023-30639 is a stored XSS vulnerability that allows a remote authenticated malicious user to store malicious HTML or JavaScript code in a trusted application data store.
Which versions of Archer Platform are affected by CVE-2023-30639?
Archer Platform versions between 6.8.0.0 and 6.11.0.4, as well as versions between 6.12.0.0 and 6.12.0.6.1, are affected by CVE-2023-30639.
How can I fix CVE-2023-30639 in Archer Platform?
To fix CVE-2023-30639, upgrade Archer Platform to version 6.12 P6 HF1 (6.12.0.6.1) or later.