First published: Fri Jul 07 2023(Updated: )
A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Unifi Network Application | <=7.3.83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32000 is a Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier).
The severity of CVE-2023-32000 is medium with a CVSS score of 4.8.
A malicious actor with Site Administrator credentials can exploit CVE-2023-32000 by persuading an Administrator to visit a malicious web page.
To fix CVE-2023-32000, update UniFi Network to version 7.3.84 or later.
You can find more information about CVE-2023-32000 in the Security Advisory Bulletin released by UniFi Network: [link](https://community.ui.com/releases/Security-Advisory-Bulletin-034-034/53cfcb84-b42b-4f8f-afbf-07c0ca7cabe2).