CVE-2023-37223: XSS
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Archer Platformto a version that resolves this vulnerability.Fixed in 6.12.0.6 - Upgrade
Upgrade
Archer Platformto a version that resolves this vulnerability.Fixed in 6.13.0
Event History
Frequently Asked Questions
What is the vulnerability ID for the Cross Site Scripting (XSS) vulnerability in Archer Platform?
The vulnerability ID is CVE-2023-37223.
What is the severity of CVE-2023-37223?
The severity of CVE-2023-37223 is medium (5.4).
How does the Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 affect the system?
The vulnerability allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
Is the Cross Site Scripting (XSS) vulnerability fixed in Archer Platform v.6.12.0.6?
Yes, the vulnerability is fixed in Archer Platform v.6.12.0.6.
Where can I find more information about the Cross Site Scripting (XSS) vulnerability in Archer Platform?
You can find more information about the Cross Site Scripting (XSS) vulnerability in Archer Platform at the following references: [Archer Community Security Advisories](https://www.archerirm.community/t5/security-advisories/archer-update-for-multiple-vulnerabilities/ta-p/702362) and [ArcherIRM](https://archerirm.com).