CVE-2023-35759: XSS
Published Jun 23, 2023
·Updated
In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
Affected Software
1 affected component
Progress WhatsUp Gold<23.0.0
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35759.
2
What software is affected by CVE-2023-35759?
Progress WhatsUp Gold before version 23.0.0 is affected by CVE-2023-35759.
3
What is the severity of CVE-2023-35759?
CVE-2023-35759 has a severity value of 6.1, which is considered medium.
4
What is the CWE category of CVE-2023-35759?
CVE-2023-35759 falls under the CWE category 79, which is Cross-Site Scripting (XSS).
5
How can an attacker exploit CVE-2023-35759?
An unauthenticated attacker can exploit CVE-2023-35759 by executing arbitrary code in a victim's browser through a malicious input in an SNMP-related application endpoint.