CVE-2023-30958: DOM XSS in Developer mode dashboard via redirect GET parameter
Published Aug 3, 2023
·Updated
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed.
This defect was resolved with the release of Foundry Frontend 6.225.0.
Affected Software
1 affected component
Zabbix Frontend<6.225.0
Event History
Aug 3, 2023
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionSeverityWeakness
Data Sourced
10:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security defect in Foundry Frontend?
The vulnerability ID is CVE-2023-30958.
2
What is the severity rating of CVE-2023-30958?
The severity rating of CVE-2023-30958 is medium with a CVSS score of 6.1.
3
What is the affected software of CVE-2023-30958?
The affected software of CVE-2023-30958 is Zabbix Frontend up to version 6.225.0.
4
What is the impact of CVE-2023-30958?
The impact of CVE-2023-30958 is that it enables users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed.
5
How was CVE-2023-30958 fixed?
CVE-2023-30958 was fixed with the release of Foundry Frontend 6.225.0.