First published: Thu Jan 04 2024(Updated: )
OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
ocsinventory-ng OCSInventory-ocsreports | =2.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3726 has a medium severity, indicating a moderate risk of exploitation.
To fix CVE-2023-3726, update OCSInventory-ocsreports to version 2.12.1 or later to eliminate the stored XSS vulnerability.
CVE-2023-3726 specifically affects OCSInventory-ocsreports version 2.12.0.
CVE-2023-3726 is a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
CVE-2023-3726 can potentially allow attackers to steal user data and perform actions on behalf of authenticated users.